Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure
Moodle XSS / Liesbeth base CMS sensitive information disclosure
 

Index | Next | Previous | View Flat


3APA3A at SECURITY

Jul 3, 2007, 2:10 AM


Views: 1766
Permalink
Moodle XSS / Liesbeth base CMS sensitive information disclosure

Dear bugtraq[at]securityfocus.com,

1.
MustLive (mustlive at websecurity.com dot ua) reported crossite
scripting vulnerability in Moodle 1.7.1 via search parameter of
index.php, example:

http://host/user/index.php?contextid=4&roleid=0&id=2&group=&perpage=20&search=%22style=xss:expression(alert(document.cookie))%20

Detailed information (in Ukranian) http://websecurity.com.ua/1045/
Original message (in Russian) http://securityvulns.ru/Rdocument391.html

2.
Durito [damagelab] (durito at mail dot ru) reported information leak
in Liesbeth base CMS (Vendor: www.doubleflex.com), example:

http://host/config.inc

file accessible through Web contains sensitive information, including
database account.

Original message (in Russian) http://securityvulns.ru/Rdocument392.html

--
http://securityvulns.com/
/\_/\
{ , . } |\
+--oQQo->{ ^ }<-----+ \
| ZARAZA U 3APA3A } You know my name - look up my number (The Beatles)
+-------------o66o--+ /
|/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Subject User Time
Moodle XSS / Liesbeth base CMS sensitive information disclosure 3APA3A at SECURITY Jul 3, 2007, 2:10 AM

  Index | Next | Previous | View Flat
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.