|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[Full-disclosure] Advisory: SANS CMS fails to sanitize web scripting
From: Moritz Naumann (security
moritz-naumann.com)
Date: Mon Jun 16 2008 - 04:38:32 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Some monday morning fun:
SANS content management system fails to properly sanitize user inputs,
allowing for injection of malicious web script or HTML.
Prior authentication is required, limiting this issue to blog posts by
people with malicious intentions or who don't know what they're doing.
POC here: http://isc.sans.org/diary.html?storyid=4565
Search the source code for 'adsitelo' (without quotes).
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]