Release date:
Updated on: 2012-10-06
Affected Systems:
ESyndiCat Pro 2.3.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50822
Cve id: CVE-2011-5177
ESyndiCat Pro is the PHP Directory software.
ESyndiCat Pro 2.3.05 and other versions of admin/controller. php has a security vulnerability that allows remote attackers to pass parameters to admins, blocks, articles, and suggest-category through the id parameter, or the sort parameter is used to input any Web script or HTML to the search page.
<* Source: d3v1l
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/demo/admin/controller.php? File = admins & amp; do = edit & amp; id = XSS
Http://www.example.com/demo/admin/controller.php? File = blocks & amp; do = edit & amp; id = XSS
Http://www.example.com/demo/admin/controller.php? Plugin = articles & amp; do = edit & amp; id = XSS
Http://www.example.com/demo/admin/controller.php? File = suggest-category & amp; id = XSS
Http://www.example.com/demo/admin/controller.php? File = search & amp; _ dc = 1322239437555 & amp; action = get & amp; start = 0 & amp; limit = 10 & amp; amp; sort = XSS
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ESyndiCat Pro
-------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.esyndicat.com/