Full Disclosure mailing list archives

Re: Ektron CMS TakeOver Part (2) - PaylPal-Forward.com demonstration


From: Benji <me () b3nji com>
Date: Wed, 5 Feb 2014 11:45:34 +0000

s/with their Facebook or Twitter credentials//g


On Tue, Feb 4, 2014 at 10:51 PM, security curmudgeon
<jericho () attrition org>wrote:


: From: Mark Litchfield <mark () securatary com>

: As previously stated, I would post an update for Ektron CMS bypassing :
the security fix.


: A full step by step with the usual screen shots can be found at - :
http://www.securatary.com/vulnerabilities

Uh... you expect people to login to your site with their Facebook or
Twitter credentials, to access these advisories?


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: