New User, Welcome!     Login

Next Page >>

Penetration Testing

[HACKATTACK Advisory 080110] Windows Live Messenger 2009 ActiveX DoS Vulnerability

Not Vulnerable:
Windows Live Messenger 2009 on Windows XP

Credits:
HACKATTACK IT SECURITY GmbH
Penetration Testing in Deutschland - sterreich - Schweiz
www.hackattack.com

and

Natal Networks Inc.

ToorCon Final Lineup Announcement

up and run any of the standard mesh-networking protocols. This
workshop is run by the guys that run the Seattle Wireless community
network and have extensive experience with setting up wireless
networks all around the world.

Crash Course in Penetration Testing
Instructor: Joseph McCray
Availability: 5 seats left

This workshop has received a lot of attention recently and is filling
up quick. The premise behind this workshop is that the first half of

Drupal CKEditor 3.0 - 3.6.2 - Persistent EventHandler XSS

# Exploit Title: Drupal CKEditor 3.0 - 3.6.2 - Persistent EventHandler XSS
# Google Dork: "inurl:"sites/all/modules/ckeditor" -drupalcode.org" 
# Google Results: Approximately 379.000 results
# Date: 18th January 2012
# Author: MaXe @InterN0T (Found in a private Hatforce.com Penetration
Test)
# Software Link: http://ckeditor.com/ & http://drupal.org/node/1332022
# Version: 3.0 - Current 3.6.2 (Drupal module: 6.x-1.8)
# Screenshot: http://i.imgur.com/8TP6w.png
# Tested on: Windows + FireFox 8.0 & Internet Explorer 8.0


Novell eDirectory 8.8 SP5 Denial of Service

********************************************************************************
Credits:
HACKATTACK IT SECURITY GmbH
Penetration Testing in Deutschland - sterreich - Schweiz
www.hackattack.com



********************************************************************************

ToorCon Final Lineup Announcement

up and run any of the standard mesh-networking protocols. This
workshop is run by the guys that run the Seattle Wireless community
network and have extensive experience with setting up wireless
networks all around the world.

Crash Course in Penetration Testing
Instructor: Joseph McCray
Availability: 5 seats left

This workshop has received a lot of attention recently and is filling
up quick. The premise behind this workshop is that the first half of

XSS vulnerability in PluXml

Vulnerable Version: 5.0.1 and probably prior versions
Vendor Notification: 29 September 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/core/admin/article.php" script to properly sanitize user-supplied input in "content" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in CruxPA

Vulnerable Version: 2.00 and Probably Prior Versions
Vendor Notification: 21 June 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/newtodo.php" script to properly sanitize user-supplied input in "todo" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

SQL Injection in HTML-EDIT CMS

Vulnerable Version: 3.1.8
Vendor Notification: 02 December 2010 
Vulnerability Type: SQL Injection
Status: Fixed by Vendor
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in nuser variable.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.


SQL injection vulnerability in TomatoCMS

Vulnerable Version: 2.0.6 and Probably Prior Versions
Vendor Notification: 14 June 2010 
Vulnerability Type: SQL Injection
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the search script to properly sanitize user-supplied input in "q" variable. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.

Attacker can use browser to exploit this vulnerability. The following PoC is available:

XSS vulnerability in VaM Shop

Vulnerable Version: 1,60 and probably prior versions
Vendor Notification: 28 December 2010 
Vulnerability Type: Stored XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "admin/configuration.php" script to properly sanitize user-supplied input in "STORE_NAME" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS in CompactCMS

Vulnerable Version: 1.4.1
Vendor Notification: 04 November 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Fixed by Vendor
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "Comments" module to properly sanitize user-supplied input in "website" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Re: XSS vulnerability in Pluck

: Vulnerable Version: 4.6.3 and probably prior versions
: Vendor Notification: 15 September 2010 
: Vulnerability Type: XSS (Cross Site Scripting)
: Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
: Risk level: Medium 
: Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

: Vulnerability Details:
: User can execute arbitrary JavaScript code within the vulnerable application.
: 
: The vulnerability exists due to failure in the 

Cross Site Scripting vulnerability in Diferior

Vulnerable Version: 8.03 and probably prior versions
Vendor Notification: 25 November 2010 
Vulnerability Type: Stored XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "views/admin.php" script to properly sanitize user-supplied input in "subcatname" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

SQL injection vulnerability in CMSQLite

Vulnerable Version: 1.3 and Probably Prior Versions
Vendor Notification: 29 June 2010 
Vulnerability Type: SQL Injection
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/admin/helper/createNewCategory.php" script to properly sanitize user-supplied input in "catName" or "catDesc" variables. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.

Attacker can use browser to exploit this vulnerability. The following PoC is available:

HTB22851: SQL Injection in WP Forum Server wordpress plugin

Vendor: VastHTML ( http://lucidcrew.com/ ) 
Vulnerable Version: 1.6.5
Vendor Notification: 10 February 2011 
Vulnerability Type: SQL Injection
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "index.php" script to properly sanitize user-supplied input in "search_max" variable.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.


Information disclosure in BloofoxCMS

Vulnerable Version: 0.3.5 and probably prior versions
Vendor Notification: 13 October 2010 
Vulnerability Type: Information Disclosure
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in key variable, it's possible to generate an sql query error that will reveal the database tables prefix.

The following PoC is available:

Stored XSS vulnerability in Zomplog

Vulnerable Version: 3.9 and probably prior versions
Vendor Notification: 13 October 2010 
Vulnerability Type: Stored XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/admin/settings_menu.php" script to properly sanitize user-supplied input in "about" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

SQL injection vulnerability in i-Web Suite

Vulnerable Version: Current at 27.07.2010 and Probably Prior Versions
Vendor Notification: 27 July 2010 
Vulnerability Type: SQL Injection
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
An attacker can disclose arbitrary local file content.

The vulnerability exists due to failure in the "default.asp" script to properly sanitize user-supplied input in multiple variables. An attacker can compromise the application, get configuration and password files content. Access to this information could lead attacker in launching further attacks against the target system.

XSS vulnerability in Expression CMS

Vulnerable Version: Current at 18.09.2010 and Probably Prior Versions
Vendor Notification: 22 September 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "contact us" page to properly sanitize user-supplied input in "section_copy_id" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in SyndeoCMS

Vulnerable Version: 2.9.0 and Probably Prior Versions
Vendor Notification: 12 July 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the save_message script to properly sanitize user-supplied input in "message" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in BXR

Vulnerable Version: 0.6.8 and Probably Prior Versions
Vendor Notification: 22 July 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Fixed by Vendor
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/settings/update_settings" script to properly sanitize user-supplied input in "setting[site_title]" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in WonderCMS

Vulnerable Version: 0.3.3 and probably prior versions
Vendor Notification: 21 December 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "editText.php" script to properly sanitize user-supplied input in "content" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in MemHT Portal

Vulnerable Version: 4.0.1 and probably prior versions
Vendor Notification: 19 October 2010 
Vulnerability Type: Stored XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/admin/pages/users/index.php" script to properly sanitize user-supplied input in "adm_sito" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in CruxPA

Vulnerable Version: 2.00 and Probably Prior Versions
Vendor Notification: 21 June 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/newtelephone.php" script to properly sanitize user-supplied input in multiple variables. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Path disclosure in Tribiq CMS

Vulnerable Version:  5.2.5 and probably prior versions 
Vendor Notification: 05 October 2010 
Vulnerability Type: Path disclosure
Status: Fixed by Vendor
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in "cType", "cID" variables, it's possible to generate an error that will reveal the full path of the script.
A remote user can determine the full path to the web root directory and other potentially sensitive information.


HTB22883: XSS vulnerability in LotusCMS

Vendor: Arboroia Network ( http://www.lotuscms.org/ ) 
Vulnerable Version: 3.0.3 and probably prior versions
Vendor Notification: 01 March 2011 
Vulnerability Type: Stored XSS (Cross Site Scripting)
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "core/model/GeneralSettingsModel.php" script to properly sanitize user-supplied input in "title" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in the search module of synType CMS

Vulnerable Version: V.0.12.2 and Probably Prior Versions
Vendor Notification: 03 June 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the search script to properly sanitize user-supplied input in "search" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in Spitfire search

Vulnerable Version: 1.0.336 and Probably Prior Versions
Vendor Notification: 08 July 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/site/cont_index.php" script to properly sanitize user-supplied input in "search" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in BlogBird platform

Vulnerable Version: Current actual version on http://www.blogbird.nl/
Vendor Notification: 13 October 2010 
Vulnerability Type: Stored XSS (Cross Site Scripting)
Status: Fixed by Vendor
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the blog setting save script to properly sanitize user-supplied input in "title" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Directory Traversal Vulnerability in FTP Commander Deluxe

Vulnerable Version: 9.20 and Probably Prior Versions
Vendor Notification: 19 July 2010 
Vulnerability Type: Directory Traversal Vulnerability
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
When exploited, this vulnerability allows an anonymous attacker to write files to specified locations on a user's system.

The FTP client does not properly sanitise filenames containing directory traversal sequences that are received from an FTP server, for example

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!