poc2
Critical Unrestricted File Upload vulnerability found @ Web-Based Teaching System (Myanmar) URL : http://www.wbts.com.mm

Malicious Attacker can upload some file to server without permission ! And It has persistent XSS vulnerability.

Cross Site Scripting is a client-side attack where an attacker can craft a malicious link, containing script- code which is then executed within the victim’s browser when the target site vulnerable to and injected with XSS is viewed. The script-code can be any language supported by the browser but mostly HTML and Javascript is used along with embedded Flash, Java or ActiveX.

poc3

In some cases where the XSS vulnerability is persistent as described further below, the attacker will not have to craft a link as the injected script is inserted directly into the target site and / or web application. The target user(s) still has to view the affected site / page where the injected code is located though.

The persistent XSS can be triggered just by browsing a Web Application with code injected into it. (This depends on which page has code injected, in case the target is not globally affected on all pages loaded by the user.)

Details

=======

Used Product :  ColdFusion 9

Vulnerability Type : Unrestricted File Upload & Persistent XSS

Security Risk : Critical

Effected URL : http://www.wbts.com.mm/dcs/act_reg.cfm

CVE : CVE-2005-0254

CVE URL : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE2005-0254

Informed to :- Webmaster

This is vulnerability is posted at Vulnerabilities Research Page : http://www.planetcreator.net/category/hacking/

We hope that your security staff will look into this issue and fix it as soon as possible.

Explore More

IP spoofing

IP spoofing is about the most advanced attack that can be executed on a computer system. IP spoofing, if done correctly, is one of the smoothest and hardest attacks on

Yatanarpon Web Portal is being hacked!

According to PeopleMediaVoice, Nation Web Portal of Myanmar ( Yatanarpon Web Portal) is being hacked by a hacker group named themselves “Humpty Dumpty”, defaced home page at around 12:30 AM

Hard disk data recovery – Recover from damaged disk? Wipe out the harddisk to avoid spying

Think of the time you take to copy a 1 GB file to the hard disk drive and the time taken to delete the same file. Doesn’t it take very