ASP Calendar Vulnerability <www.ashiyane.com>
From: ali reza AcTiOnSpIdEr (actionspider_at_gmail.com)
Date: 12/14/04
- Previous message: Martin Schulze: "[SECURITY] [DSA 609-1] New atari800 packages fix local root exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 14 Dec 2004 10:59:57 -0000 To: bugtraq@securityfocus.com('binary' encoding is not supported, stored as-is)
<< www.ashiyane.com >>
Release by AcTiOnSpIdEr
AcTiOnSpIdEr@gmail.com
Advisory Name: ASP Calendar Vulnerability
Release Date:13 December 2004
Platform:Any website using asp Calendar
Severity:no password protected !
Overview :
----------
ASP Calendar is a tool written in aps to handle the administration page(( Control Panel ))
you can in this control panel Add Event View/EditEvents
Add Category View Categories
Vulnerability :
---------------
control panel in asp clendar no protcted wiht password
you can go this page wiht url !
exampel:
www.victem.com/***/admin/main.asp
*** : dirctory that asp cleander is instaling
you can find it to search in google <admin/main.asp>
tanQ
and bye;)
- Previous message: Martin Schulze: "[SECURITY] [DSA 609-1] New atari800 packages fix local root exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]