iDEV Forums

Please login or register.

Login with username, password and session length
Advanced search  

News:

IDEVSPOT COMMUNITY FORUMS. -----( ( ( NOT FOR OFFICIAL TECH SUPPORT ) ) )-----

Author Topic: Delete.PHP Authentication Bypass Vulnerability  (Read 2464 times)

0 Members and 1 Guest are viewing this topic.

abhishek

  • Newbie
  • *
  • Posts: 2
    • View Profile
Delete.PHP Authentication Bypass Vulnerability
« on: April 06, 2008, 11:50:12 PM »
hey arron,
NixieAffiliate 1.9 has got a vulnerability.
See http://www.securityfocus.com/bid/20086
I saw this on google.
All NixieAffiliate1.9 owners will be affected with this.
Try to find out a solution to this and fix it.
Ive also sent you a PM regarding this.

Here is the problem
====================================================
NixieAffiliate all version bypass admin and xss Sep 16 2006 10:30PM
by ali@ hackerz.ir
NixieAffiliate all version

vendor : idevspot.com

By : s3rv3r_hack3r

www: hackerz.ir & h4ckerz.com

Bypass for delete any aff ID :>>

www.domain.com/NixieAffiliate/delete.php?id=1

Xss :>>

www.domain.com/NixieAffiliate/forms/lostpassword.php?error=[xss]
====================================================
« Last Edit: April 07, 2008, 12:08:09 AM by abhishek »
Logged

arron

  • iDevSpot
  • Administrator
  • Hero Member
  • *****
  • Gender: Male
  • Posts: 1202
    • View Profile
    • WWW
Re: Delete.PHP Authentication Bypass Vulnerability
« Reply #1 on: April 10, 2008, 01:08:36 PM »
This was fixed quite some time ago. :)
Logged

Join our Facebook Fan Page to receive special offers & update information : http://www.facebook.com/pages/iDevSpot/157097554841