Aerosol Posted September 25, 2014 Report Posted September 25, 2014 Information-----------Advisory by Netsparker.Name : LFI Vulnerability in OsClassAffected Software : OsClassAffected Versions: 3.4.1 and possibly belowVendor Homepage : http://osclass.org/Vulnerability Type : Local File InclusionSeverity : CriticalCVE-ID: CVE-2014-6308Netsparker Advisory Reference : NS-14-031Advisory URL------------https://www.netsparker.com/lfi-vulnerability-in-osclass/Description-----------Local file inclusion vulnerability where discovered in Osclass, anopen source project that allows you to create a classifieds sites.Technical Details-----------------Proof of Concept URL for LFI in OsClass:http://example.com/osclass/oc-admin/index.php?page=appearance&action=render&file=../../../../../../../../../../etc/passwdAdvisory Timeline-----------------03/09/2014 - First Contact03/09/2014 - Vulnerability fixed:https://github.com/osclass/Osclass/commit/c163bf5910d0d36424d7fc678da6b03a0e44343515/09/2014 - Fix released publicly in Osclass 3.4.2Credits & Authors-----------------These issues have been discovered by Omar Kurt while testingNetsparker Web Application Security Scanner.About Netsparker----------------Netsparker can find and report security issues and vulnerabilitiessuch as SQL Injection and Cross-site Scripting (XSS) in all websitesand web applications regardless of the platform and the technologythey are built on. Netsparker's unique detection and exploitationtechniques allows it to be dead accurate in reporting hence it's thefirst and the only False Positive Free web application securityscanner. For more information on Netsparker visithttps://www.netsparker.com.Source Quote
QUADMACHINE Posted September 25, 2014 Report Posted September 25, 2014 Pacat ca olx belix au permisiuni din httaces pe oc-admin. Quote