Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Advisory: SANS CMS fails to sanitize web scripting
From: Moritz Naumann <security () moritz-naumann com>
Date: Mon, 16 Jun 2008 09:38:32 +0000

Some monday morning fun:

SANS content management system fails to properly sanitize user inputs,
allowing for injection of malicious web script or HTML.
Prior authentication is required, limiting this issue to blog posts by
people with malicious intentions or who don't know what they're doing.

POC here: http://isc.sans.org/diary.html?storyid=4565

Search the source code for 'adsitelo' (without quotes).

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • Advisory: SANS CMS fails to sanitize web scripting Moritz Naumann (Jun 16)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]