Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: e107 website system Vulnerability

Re: e107 website system Vulnerability

From: Tjebbe de Winter <Tjebbe.deWinter__at_nospam.cysonet.com>
Date: Fri, 25 Jul 2003 17:13:15 +0200

On Thu, Jul 24, 2003 at 03:30:43PM -0500, nokio x0 wrote:
> Heh, I every site that i've come across running the e107 portal seems to ask
> for admin login before you could use this exploit...Are you sure all
> versions are vulnerable? Doesn't even work on my own system without asking
> for login.

See: http://e107.org/news.php

If you post the dump_sql variable with method POST, it'll work.

Regards,

---
 Tjebbe...
-------------------------------------------------------------------------------
Tjebbe de Winter    |      Cysonet  Managed  Hosting      |  tjebbe @ cysonet.com
tel. +31 20 4703339 |       Managing the buzzwords.       |  http://cyso.nl
-------------------------------------------------------------------------------
Received on Jul 25 2003
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos