mailing list archives
phpAdultSite CMS flaws
From: SmOk3 <smok3f00 () gmail com>
Date: Sun, 7 Sep 2008 18:20:20 +0100
phpAdultSite CMS is a PHP-based content management system for a adult
pay site that fully supports MySQL. The code, layout, graphics of
phpAdultSite are consistent through every single page of your site.
It costs between $400 to $1100 depending on the license.
I found that this script is vulnerable to a couple of topics. After no
reply of this CMS vendors, send about two emails 1 week ago, I decided
going to full disclosure.
The problem exists on results_per_page variable. If it returns false,
it gives a DB Error output on our browser, showing up path disclosure,
sql statments that may lead to sql injections and also, it executes
It can be fixed with the sanitize of the variable.
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- phpAdultSite CMS flaws SmOk3 (Sep 07)