[Owasp-cuiaba] Fwd: [Full-disclosure] 495 vulnerabilities on thelia

Kembolle Amilkar haxorcoding em gmail.com
Quinta Julho 26 15:52:15 UTC 2012


encaminhando....

*Att. Kembolle Amilkar *
#/[ kembolle.com.br <http://www.kembolle.com.br> ] - Consultoria Segurança
da Informação.
#/ [ samurayconsultoria.com.br ] - Chief Security Officer - Samuray
Consultoria.
#/ Systems Analyst | Esp. Information Security | Computer Forensic Expert |
#/ Owasp Chapter Lider Cuiabá - https://www.owasp.org/index.php/Cuiaba
#/ Mobile: [65] 9979-2925  && contato[at]kembolle.com.br.
**



---------- Forwarded message ----------
From: HTTPCS <contact em httpcs.com>
Date: 2012/7/25
Subject: [Full-disclosure] 495 vulnerabilities on thelia
To: full-disclosure em lists.grok.org.uk


**

HTTPCS Advisory : HTTPCS30
Product : Thelia
Version : 1.5.1
Date : 2012-07-11
Criticality level : Less Critical
Description : A vulnerability has been discovered in Thelia, which can be
exploited by malicious people to conduct cross-site scripting attacks.
Input passed via the 'lang' parameter to '/message_modifier.php' is not
properly sanitised before being returned to the user. This can be exploited
to execute arbitrary HTML and script code in a user's browser session in
context of an affected site.
Page : /message_modifier.php
Variables : lang=[VulnHTTPCS]
Type : XSS
Method : GET
Solution :
References : https://www.httpcs.com/advisory/httpcs30
Credit : HTTPCS [Web Vulnerability Scanner]

-----------------------------------------------------------------

HTTPCS Advisory : HTTPCS46
Product : Thelia
Version : 1.5.1
Date : 2012-07-11
Criticality level : Less Critical
Description : A vulnerability has been discovered in Thelia, which can be
exploited by malicious people to conduct cross-site scripting attacks.
Input passed via the 'id' parameter to '/contenu_modifier.php' is not
properly sanitised before being returned to the user. This can be exploited
to execute arbitrary HTML and script code in a user's browser session in
context of an affected site.
Page : /contenu_modifier.php
Variables : id=[VulnHTTPCS]
Type : XSS
Method : GET
Solution :
References : https://www.httpcs.com/advisory/httpcs46
Credit : HTTPCS [Web Vulnerability Scanner]


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
-------------- Próxima Parte ----------
Um anexo em HTML foi limpo...
URL: <http://lists.owasp.org/pipermail/owasp-cuiaba/attachments/20120726/b66a8e16/attachment.html>


More information about the Owasp-cuiaba mailing list