Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Vulnerability to Firebook

Go down

Vulnerability to Firebook Empty Vulnerability to Firebook

Post  andry Wed Aug 11, 2010 10:50 pm

There was found the Information Leakage, Cross-Site Request Forgery, Cross-Site Scripting, Directory Traversal and Full path disclosure vulnerabilities in Firebook. This guest

book. These vulnerabilities I found on exwp.com. What soon inform developers.

Details of vulnerabilities will come soon. First, inform web application developers.

Information Leakage:

Code:

http://site/path_to_firebook_admin/?URLproxy=http://firebook.ru/env/index.html;

CSRF:

Code:

http://site/path_to_firebook_admin/?URLproxy=http://site;

Possible CSRF-attacks on other sites.

XSS:

[code:1:7c05]
http://site/path_to_firebook_admin/?URLproxy =% 3Cscript% 3Ealert (document
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum