|
|||||||||||
|
Reporting Vulnerable Public Web mail
From: <ivan.sanchez(at)nullcode.com.ar>
Date: Fri Oct 05 2007 - 13:58:04 EDT
Technical Details: +===========================================================================+ Author(s): Ivan Sanchez & Maximiliano Soler Product: MailBee WebMail Pro 3.4 Web: http://www.afterlogic.com/ Versions: 3.4 (or less) Date: 05/10/2007 Not Vulnerable: 4.0 (or superior) GOOGLE DORKS: [+] intitle:"MailBee WebMail" [+] intext:"Powered by MailBee WebMail" EXPLOIT: For example...after the variable "mode2" or "mode" http://www.[DOMAIN].tld/[PATH]/login.php?mode=[XSS] http://www.[DOMAIN].tld/[PATH]/default.asp?mode=advanced_login&mode2=[XSS]
NULL CODE SERVICES [ www.nullcode.com.ar ] Hunting Security Bugs!
Ivan Javier Sanchez
Tel-Fax 011-4276-2399
Cel-154879059
www.nullcode.com.ar This message was sent using IMP, the Internet Messaging Program.
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:19:30 EDT |
||||||||||
|
|||||||||||