The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


[Kurdish Security # 9] MyMail Directory Traversal And XSS


<< Previous INDEX Search src / Print Next >>
Date: 26 Jun 2006 13:20:50 -0000
From: botan@linuxmail.org
To: bugtraq@securityfocus.com
Subject: [Kurdish Security # 9] MyMail Directory Traversal And XSS
 Attacking Vulnerability
X-Virus-Scanned: antivirus-gw at tyumen.ru

# Kurdish Security Advisory
# irc.gigachat.net #kurdhack
# Discovered by Botan 
# http://scripts.codingclick.com/MyMail/

http://kurdishsecurity.blogspot.com/2006/06/kurdish-security-9-mymail-directory.html

CodingClick.com MyMail Script is useing for scripts.The passing can do between directory. Examine..

Now only first Directory Traversal vuln

Vulnerable Version = 0.x

http://www.site.com/[MyMail_path]/admin/
http://www.site.com/[MyMail_path]/admin/list.php?action=add
http://www.site.com/[MyMail_path]/admin/email.php?action=add or /delete
http://www.site.com/[MyMail_path]/admin/export.php
http://www.site.com/[MyMail_path]/admin/archive.php?Action=add or /delete


Now XSS attacking looking

Vulnerable Version = 1.0 Beta

http://www.site.com/[MyMail_path]/admin/login.php=error=[XSS]


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру