what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

In-Portal CMS 5.2.0 Cross Site Scripting

In-Portal CMS 5.2.0 Cross Site Scripting
Posted Sep 16, 2014
Authored by MustLive

In-Portal CMS versions 5.2.0 and below suffer from cross site scripting and brute forcing vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | e170753396594323bee4e2556fe03110708728dffbab6e52cabc4c2ee30b0a89

In-Portal CMS 5.2.0 Cross Site Scripting

Change Mirror Download
Hello list!

These are Cross-Site Scripting and Brute Force vulnerabilities in In-Portal
CMS.

-------------------------
Affected products:
-------------------------

Vulnerable are In-Portal CMS 5.2.0 and previous versions.

In version In-Portal CMS 5.2.1 at 31.08.2014 developers fixed XSS
vulnerability after my warning. But didn't fix BF, only gave recommendations
about protection against these attacks (it's their solution). They recommend
for users of the system to limit access to admin panel by IP.

-------------------------
Affected vendors:
-------------------------

In-Portal
http://in-portal.com

----------
Details:
----------

Cross-Site Scripting (WASC-08):

http://site/admin/index.php?env=-login:m0--1--s-&next_template=%22%3E%3Cbody%20onload=alert(document.cookie)%3E

Brute Force (WASC-11):

http://site/admin/index.php

I mentioned about these vulnerabilities at my site
(http://websecurity.com.ua/7276/).

Best wishes & regards,
Eugene Dokukin aka MustLive
Administrator of Websecurity web site
http://websecurity.com.ua




Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close