New User, Welcome!     Login

External Links

[InterN0T] SiteCore.NET 6.0.0 - XSS Vulnerability

Info: It's an overpriced CMS for companies running IIS.

Credits: InterN0T

External Links:
http://sitecore.net/


-:: The Advisory ::-


[InterN0T] ShareTronix 1.0.4 - HTML Injection Vulnerability

Credits: MaXe from InterN0T (patched the vulnerability) & Reelix (found the vulnerability)



External Links:

http://sharetronix.com/opensource/




[InterN0T] Google Analytics plugin for Wordpress - XSS Vulnerability

AdSense clicks, add extra search engines, track image search queries and it
will even work together with Urchin.

Credits: InterN0T

External Links:
http://yoast.com/wordpress/google-analytics/


-:: The Advisory ::-
On line 353 in googleanalytics.php the following vulnerable code was identified:

[InterN0T] Pivot 1.40.4-7 - Multiple Vulnerabilities

completely free to use. It is written in PHP, and does not require
additional libraries or databases to function.

Credits: InterN0T

External Links:
http://www.pivotlog.net/


-:: The Advisory ::-


[InterN0T] transLucid 1.75 - Multiple Vulnerabilities

Info: transLucidonline is the easy website publishing system with which anyone can create and maintain web content, in multiple languages and based on a growing list of ready-made, professional layouts. 

Credits: InterN0T (macd3v and MaXe)

External Links:
http://www.pantha.net/


-:: The Advisory ::-


[InterN0T] Webmedia Explorer - XSS Vulnerability

Info: Webmedia Explorer is the alternative CMS engine that reads the hard disc and generates a website realtime taking advantage of a very powerful rendering and data fetching caching system.

Credits: InterN0T

External Links:
http://www.webmediaexplorer.com/


-:: The Advisory ::-


Jira Enterprise 4.0.1 - Multiple Low Risk Vulnerabilities

Info:
JIRA provides issue tracking and project tracking for software
development teams to improve code quality and the speed of
development. (and so forth.)

External Links:
http://www.atlassian.com/software/jira/

Credits: MaXe (no previous vulnerability information about these
bugs were found.)


[InterN0T] Flatnux 2009-03-27 - XSS Vulnerabilities + More

Info: See website for more information.

Credits: InterN0T

External Links:
http://www.flatnux.altervista.org/


-:: The Advisory ::-


Re: Seo Panel 2.1.0 - Critical File Disclosure

> 
> Info:
> A complete open source seo control panel for managing search engine optimization of your websites.
> Seo Panel is a seo tool kit includes latest hot seo tools to increase and track the performace of your websites.
> 
> External Links:
> http://www.seopanel.in/
> 
> Credits: MaXe (@InterN0T)
> 
> 

[InterN0T] Geeklog 1.5 - Pre-Installation Vulnerabilities

Opinion: The system seems to be more secure than most web application systems on the Internet these days.

Credits: InterN0T

External Links:
http://www.geeklog.net/


-:: The Advisory ::-


[InterN0T] moziloCMS 1.11.1 - XSS Vulnerability

Info: See website for more information. (It's in german and i don't bother translating)

Credits: InterN0T

External Links:
http://cms.mozilo.de/


-:: The Advisory ::-


[InterN0T] LightNEasy 2.2.2 - HTML Injection Vulnerability

Info: LightNEasy, a simple and light Content Management System and Website Builder

Credits: InterN0T

External Links:
http://lightneasy.org/


-:: The Advisory ::-


[InterN0T] TBDev 01-01-2008 - Multiple Vulnerabilities

Info: TBDEV.NET is a project to further enhance, update and develop a software (php peer-to-peer) from the original torrentbits/bytemonsoon source code.

Credits: InterN0T

External Links:
http://www.tbdev.net


-:: The Advisory ::-


Seo Panel 2.1.0 - Critical File Disclosure

 
Info:
A complete open source seo control panel for managing search engine optimization of your websites.
Seo Panel is a seo tool kit includes latest hot seo tools to increase and track the performace of your websites.
 
External Links:
http://www.seopanel.in/
 
Credits: MaXe (@InterN0T)
 
 

[InterN0T] LiveZilla - XSS Vulnerability

LiveZilla to provide Live Chats and monitor your website visitors
in real-time. Convert visitors to customers - with LiveZilla!

Credits: InterN0T

External Links:
http://www.livezilla.net/


-:: The Advisory ::-
The following files would together be vulnerable to Cross Site Scripting.

Drupal CKEditor 3.0 - 3.6.2 - Persistent EventHandler XSS

results users
have when publishing it. It brings to the web common editing features
found on desktop
editing applications like Microsoft Word and OpenOffice.
 
External Links:
http://ckeditor.com/
http://drupal.org/node/1332022
 
Credits: MaXe (@InterN0T) - Hatforce.com
 

vBulletin 4.0.8 - Persistent XSS via Profile Customization

Content publishing, search, security, and more— vBulletin has it all.
Whether it’s available features, support, or ease-of-use, vBulletin offers
the most for your money. Learn more about what makes vBulletin the
choice for people who are serious about creating thriving online communities.

External Links:
http://www.vbulletin.com

Credits: MaXe (@InterN0T)



vBulletin 4.0.8 PL1 - XSS Filter Bypass within Profile Customization

Content publishing, search, security, and more - vBulletin has it all.
Whether it's available features, support, or ease-of-use, vBulletin offers
the most for your money. Learn more about what makes vBulletin the
choice for people who are serious about creating thriving online communities.

External Links:
http://www.vbulletin.com

Credits: MaXe (@InterN0T)



vBulletin - Insecure Custom BBCode Tags

Content publishing, search, security, and more—vBulletin has it all. Whether
it’s available features, support, or ease-of-use, vBulletin offers the most for
your money. Learn more about what makes vBulletin the choice for people
who are serious about creating thriving online communities.

External Links:
http://www.vbulletin.com/



-:: The Advisory ::-

[InterN0T] Achievo 1.3.4 - XSS Vulnerability

inurl:/achievo/index.php intitle:achievo

However, why would One need a Googled0rk when One can just look here?
http://www.achievo.org/product/testimonials/

External Links:
http://www.achievo.org/
http://www.achievo.org/download/
http://www.achievo.org/demo/

Default Admin User:

[InterN0T] AMember 3.1.7 - Multiple Vulnerabilities

http://lmgtfy.com/?q=inurl:/amember intext:© CGI-Central.NET, 2002-2006

Inaccurate Googled0rk: (more results)
http://lmgtfy.com/?q=intext:© CGI-Central.NET, 2002-2006

External Links:
http://www.amember.com/
http://www.amember.com/p/Main/Download
http://www.amember.com/p/Main/Demo



[InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities

Credits: Matt and all of InterN0T :-)

Googled0rk: (there might be more accurate d0rks)
intitle:"Advertisement Management Control Panel"

External Links:
http://www.adpeeps.com/
http://www.adpeeps.com/signup.html
http://demo.adpeeps.com/index.php?loc=adminlogin&uid=100000

Default Login:

[InterN0T] SkyBlueCanvas 1.1 r237 - Multiple Vulnerabilities

Info: SkyBlueCanvas Lightweight CMS is an open source, free content management system written in php and built specifically for small web sites. The entire site you are viewing is a demonstration of the SkyBlueCanvas lightweight CMS. SkyBlueCanvas is custom-built for those instances when more robust systems like Joomla, WordPress and Drupal are too much horsepower.

Credits: InterN0T

External Links:
http://www.skybluecanvas.com


-:: The Advisory ::-


RE: vBulletin - Critical Information Disclosure

Content publishing, search, security, and more-vBulletin has it all. Whether
it's available features, support, or ease-of-use, vBulletin offers the most
for your money. Learn more about what makes vBulletin the choice for people
who are serious about creating thriving online communities.

External Links:
http://www.vbulletin.com/


-:: The Advisory ::-
vBulletin is prone to information disclosure of the entire database

vBulletin - Critical Information Disclosure

Content publishing, search, security, and more—vBulletin has it all. Whether
it’s available features, support, or ease-of-use, vBulletin offers the most for
your money. Learn more about what makes vBulletin the choice for people
who are serious about creating thriving online communities.

External Links:
http://www.vbulletin.com/


-:: The Advisory ::-
vBulletin is prone to information disclosure of the entire database



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!