SecurityAlert : 10 CVE : CVE-2005-2987 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : retrogod aliceposta it Published : 17.09.2005
description: "Teachers have full control through a web-based interface.
Designed
for easy installation and even easier use, the Digital Scribe has been
used in
thousands of schools. No teacher or IT Personnel needs to know any
computer
languages in order to install and use this intuitive system.
2) remote code execution
*******************************************************
now you can edit template and leave a backdoor on target system:
at the end of the footer try this:
rgod
site: http://rgod.altervista.org
email: retrogod at aliceposta it
original advisory: http://rgod.altervista.org/dscribe14.html
************************************************************************
********
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.