Security holes in 11 products...

From: frog frog (leseulfrogat_private)
Date: Sat Apr 27 2002 - 07:44:53 PDT

  • Next message: Alex Lambert: "Multiple CSS/XSS vulnerabilities on directNIC.com"

    
     ('binary' encoding is not supported, stored as-is)
    - adManager :
    v1.1
    
    Problems :
    )XSS
    )Access to an admin option
    
    - MiniBB :
    v1.2
    
    Problems :
    )XSS
    )Access to admins accounts
    
    - Secure
    
    - Trackeur
    
    - LOGS
    
    Problem :
    )Spoofing
    
    ---------------More details : --------------
    in french : 
    http://www.ifrance.com/kitetoua/tuto/5holes2.txt
    translated by google :
    http://translate.google.com/translate?u=http%3A%2F%
    2Fwww.ifrance.com%2Fkitetoua%2Ftuto%
    2F5holes2.txt&langpair=fr%7Cen&hl=fr&ie=ASCII&oe=ASCII
    --------------------------------------------
    
    - PhpWebGallery
    v1.0
    
    Problem :
    - Access to users/admins accounts
    
    ---------------More details : --------------
    in french :
    http://www.ifrance.com/kitetoua/tuto/PWG.txt
    translated by google :
    http://translate.google.com/translate?u=http%3A%2F%
    2Fwww.ifrance.com%2Fkitetoua%2Ftuto%2FPWG.txt&langpair=fr%
    7Cen&hl=fr&ie=ASCII&oe=ASCII
    --------------------------------------------
    
    - 0wn f0rum
    v2.1
    
    Problems :
    )XSS
    )Access to users/admins account
    
    - Livre d'or
    
    - Messagerie
    
    - Recherche
    
    - KvGuestbook
    
    
    ---------------More details : --------------
    in french :
    http://www.ifrance.com/kitetoua/tuto/5holes3.txt
    translated by google :
    http://translate.google.com/translate?u=http%3A%2F%
    2Fwww.ifrance.com%2Fkitetoua%2Ftuto%
    2F5holes3.txt&langpair=fr%7Cen&hl=fr&ie=ASCII&oe=ASCII
    --------------------------------------------
    
    frog-m@n
    



    This archive was generated by hypermail 2b30 : Sun Apr 28 2002 - 10:30:15 PDT