Web Wiz Site News realease v3.06 administration access.

From: drG4njubas (drG4njat_private)
Date: Mon Apr 14 2003 - 06:19:03 PDT

  • Next message: drG4njubas: "FipsGuestbook Version 1.12.7 script injection."

    Date:
    14.04.2003
    
    Subject:
    Web Wiz Site News realease v3.06 administration access.
    
    Description:
    Free asp news management system. Includes, simple intergration, 
    short news item with link to full story, insert images, links, 
    text formatting, user comments(optional) with email notification, 
    anti-spam settings, and more 
    
    Vendor:
    Web Wiz Guide
    http://www.webwizguide.info/
    
    Vulnerability:
    Administrator's password is not encrypted. It is
    placed in MS Acess database. An attaker may download 
    it and gain administrators privilegies.
    Example: http://www.target.com/news/news.mdb
    
    
    Black Tigerz Research Group
    We are:Areus,Barracuda,n1Tr0f4n,Velzevol,n3ch,drG4njubas.
    Please visit our website: http://www.blacktigerz.org  
    



    This archive was generated by hypermail 2b30 : Mon Apr 14 2003 - 10:37:58 PDT