Digital Security Research Group [DSecRG] Advisory #DSECRG-08-022
Application: BolinOS
Versions Affected: 4.6.1
Vendor URL: http://www.bolinos.com
Bugs: Local File Include,Multiple XSS, System
information disclosure
Exploits: YES
Reported: 13.03.2008
Second report: 18.03.2008
Vendor response: none
Solution: none
Date of Public Advisory: 25.03.2008
Authors: Digital Security Research Group [DSecRG]
(research [at] dsec [dot] ru)
Description
***********
BolinOS system has multiple security vulnerabilities:
1. Local File Include
2. Multiple Linked XSS vulnerabilities
3. Multiple XSS in POST
4. System information disclosure
Details
*******
1. Local File Include vulnerability found in
system/_b/contentFiles/gbincluder.php
Digital Security is leading IT security company in Russia, providing
information security consulting, audit and penetration testing services,
risk analysis and ISMS-related services and certification for ISO/IEC
27001:2005 and PCI DSS standards. Digital Security Research Group focuses
on web application and database security problems with vulnerability
reports, advisories and whitepapers posted regularly on our website.
Contact: research [at] dsec [dot] ru
http://www.dsec.ru (in Russian)
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.