Bug: Nooms 1.1 ( Ascii Version )

Search:
WLB2

Nooms 1.1

Published
Credit
Risk
2008.09.11
irancrash
Medium
CWE
CVE
Local
Remote
CWE-59
CWE-79
CWE-200
CVE-2008-4162
CVE-2008-4179
CVE-2008-4180
No
Yes

----------------------------------------------------------------

Script : Nooms 1.1

Type : Multiple Vulnerabilities (Cross Site Scripting/Redirect/Mysql Brute Force Local Access)

Risk : Medium

----------------------------------------------------------------

Download From : http://surfnet.dl.sourceforge.net/sourceforge/nooms/nooms_1.1.zip

----------------------------------------------------------------

Discovered by : Khashayar Fereidani Or Dr.Crash

My Website : http://FEREIDANI.IR

Team Website : http://IRCRASH.COM

Khashayar Fereidani Email : irancrash [ a t ] gmail [ d o t ] com

----------------------------------------------------------------

Mysql Remote Brute Force Vulnerability :


This is new type of the vulnerabilities .

I can't public Exploit of this vulnerability ,
But with this vulnerability attacker can brute force root and other user password with php in remote mode .

Mysql Brute Force Vulnerability : /db.php?g_dbhost=localhost&g_dbuser=[username]&g_dbpwd=[password]

----------------------------------------------------------------

Cross Site Scripting Vulnerabilities :

Xss 1 : http://Example/smileys.php?page_id=<script>alert('xss')</script>

Xss 2 : http://Example/search.php?q="<script>alert('xss')</script>

----------------------------------------------------------------

Redirect Vulnerability :

Xss 1 : http://Example/admin/auth.php?g_site_url=[URL]

----------------------------------------------------------------

Tnx : God

http://IRCRASH.COM http://FEREIDANI.IR

----------------------------------------------------------------

References:

http://www.securityfocus.com/archive/1/archive/1/496236/100/0/threaded

See this note in TXT Version

Bugtraq RSS
Bugtraq
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn
 
CVE RSS
CVEMAP

Copyright 2014, cxsecurity.com
Ascii Version