BugTraq
ASP Calendar Vulnerability <www.ashiyane.com> Dec 14 2004 10:59AM
ali reza AcTiOnSpIdEr (actionspider gmail com)


<< www.ashiyane.com >>

Release by AcTiOnSpIdEr

AcTiOnSpIdEr (at) gmail (dot) com [email concealed]

Advisory Name: ASP Calendar Vulnerability

Release Date:13 December 2004

Platform:Any website using asp Calendar

Severity:no password protected !

Overview :

----------

ASP Calendar is a tool written in aps to handle the administration page(( Control Panel ))

you can in this control panel Add Event View/EditEvents

Add Category View Categories

Vulnerability :

---------------

control panel in asp clendar no protcted wiht password

you can go this page wiht url !

exampel:

www.victem.com/***/admin/main.asp

*** : dirctory that asp cleander is instaling

you can find it to search in google <admin/main.asp>

tanQ

and bye;)

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus