MTCMS multiple upload vulnerabilities

看板Bugtraq作者時間19年前 (2007/02/27 07:24), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
avatar upload vulnerability: upload any kind of file in: site.com/MTCMS-V2.2/?a=gallery&b=add_down and approuved or not it will be here : /uploads/pictures/ same thing for : add link /index.php?a=links&b=add_link xss permanent on Contact Us : message & title fields are vulnerable to an xss attack. this kind of xss are pretty dangerous, because you send the malicious message to an admin. so you can get his cookie. regards laurent gaffi
文章代碼(AID): #15usmZ00 (Bugtraq)