exploit-db-mirror/platforms/php/webapps/30098.txt
Offensive Security 5a468df6b9 Updated 12_08_2013
2013-12-08 16:08:13 +00:00

10 lines
No EOL
679 B
Text
Executable file

source: http://www.securityfocus.com/bid/24210/info
Uebimiau is prone to multiple input-validation vulnerabilities, including cross-site scripting issues and an information-disclosure issue, because the application fails to properly sanitize user-supplied input.
Attackers can exploit these issues to steal cookie-based authentication credentials, to control how the site is rendered to the user, or to gain access to information that could aid in further attacks.
Uebimiau 2.7.2 and 2.7.10 are vulnerable; other versions may also be affected.
http://www.example.org/demo/pop3/error.php?smarty=test
http://www.example.org/demo/pop3/error.php?selected_theme=test