[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
New vulnerabilities in CMS SiteLogic
- To: <bugtraq@xxxxxxxxxxxxxxxxx>
- Subject: New vulnerabilities in CMS SiteLogic
- From: "MustLive" <mustlive@xxxxxxxxxxxxxxxxxx>
- Date: Fri, 19 Nov 2010 23:43:24 +0200
Hello Bugtraq!
I want to warn you about Insufficient Anti-automation and Denial of Service
vulnerabilities in CMS SiteLogic (in addition to those multiple
vulnerabilities in CMS SiteLogic which I disclosed in 2009-2010). It's
Ukrainian commercial CMS.
SecurityVulns ID: 11258.
-------------------------
Affected products:
-------------------------
Vulnerable are all versions of CMS SiteLogic with corresponding
functionality.
----------
Details:
----------
Insufficient Anti-automation (WASC-21):
http://site/?mid=1
In contact form there is no protection from automated requests (captcha).
DoS (WASC-10):
Empty POST request at page http://site in field “Search at the site” shows
all records from DB.
DoS (WASC-10):
http://site/?mid=1&action=arhiv
At the page of archive all records from DB are showing.
------------
Timeline:
------------
2010.08.31 - announced at my site.
2010.09.01 - informed developers.
2010.11.17 - disclosed at my site.
I mentioned about these vulnerabilities at my site
(http://websecurity.com.ua/4487/).
Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua