Disclosure: Annuaire (Directory) Multiple Vulnerabilities

[This was originally published on OSVDB, now gone. VulnDB IDs 24302, 24303]

Comment left on feedback page:
http://www.brunox.org/modules.php?op=modload&name=FeedBack&file=index

While testing your demo of Annuaire (Directory), I noticed a few security vulnerabilities:

Many pages are calling /include/lang-en.php which is showing the full installation path. Additionally, directly requesting this script will reveal the full path.

inscription.php The comment field (COMMENTAIRE variable) allows for cross-site scripting (XSS) attacks.

Thanks

Brian

Leave a Reply

Discover more from Rants of a deranged squirrel.

Subscribe now to keep reading and get access to the full archive.

Continue reading