Exploit Foro Domus 2.10 - Multiple Input Validation Vulnerabilities

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
27033
Проверка EDB
  1. Пройдено
Автор
ALIAKSANDR HARTSUYEU
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-0110
Дата публикации
2006-01-06
Код:
source: https://www.securityfocus.com/bid/16154/info

Foro Domus is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.

Foro Domus version 2.10 is vulnerable to these issues; other versions may also be affected. 

An example URI exploiting the cross-site scripting issue was provided:
http://www.example.com/domus/escribir.php?domus=ae29cf4d3f2dc42241e387d39b4126e2&hilo=1&padre=1&categoria=General&n=&usario=username&email=e@\';%20alert(123);%20var%20dss=\'h.co&asunto=blabla&texto=anytext&accion=enviar
 
Источник
www.exploit-db.com

Похожие темы