Advertisement
CVE | Category | Price | Severity |
---|---|---|---|
CWE-79 | Not specified | Not specified |
Author | Risk | Exploitation Type | Date |
---|---|---|---|
Not specified | Not specified | Not specified | 2006-05-31 |
CVSS | EPSS | EPSSP |
---|---|---|
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | 0.02192 | 0.50148 |
Advisory : Cross Site Scripting in Seditio (http://www.neocrome.net) Release Date : 24/05/2005 Last Modified : 24/05/2005 Author : Yunus Emre Yilmaz ( http://yns.zaxaz.com) Application : Seditio v102 ( maybe older versions) Risk : Critical Problem : Ldu's logging all referer info for administrator.If an attacker change the referer value with malicious js codes, the code will be executed in administration page.Referer info is coming from user and can be changed as everything. Proof Of Concept : I wrote a simple exploit which can be downloaded from here : http://yns.zaxaz.com/exploits/seditio-exploit.rar Solution : I wrote an unofficial security patch which can be downloaded from here : http://yns.zaxaz.com/security-patches/security-patches-seditio-v102-xss- patch.rar (For offical patches : www.neocrome.net) Original Advisory : http://yns.zaxaz.com/advisories/seditio.txt
Copyright ©2024 Exploitalert.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.