Full Disclosure mailing list archives

495 vulnerabilities on thelia


From: HTTPCS <contact () httpcs com>
Date: Wed, 25 Jul 2012 18:26:30 +0200 (CEST)

HTTPCS Advisory : HTTPCS30
Product : Thelia
Version : 1.5.1
Date : 2012-07-11
Criticality level : Less Critical
Description : A vulnerability has been discovered in Thelia, which can be
exploited by malicious people to conduct cross-site scripting attacks. Input
passed via the 'lang' parameter to '/message_modifier.php' is not properly
sanitised before being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user's browser session in context of an
affected site.
Page : /message_modifier.php
Variables : lang=[VulnHTTPCS]
Type : XSS
Method : GET
Solution :
References : https://www.httpcs.com/advisory/httpcs30
Credit : HTTPCS [Web Vulnerability Scanner]

-----------------------------------------------------------------

HTTPCS Advisory : HTTPCS46
Product : Thelia
Version : 1.5.1
Date : 2012-07-11
Criticality level : Less Critical
Description : A vulnerability has been discovered in Thelia, which can be
exploited by malicious people to conduct cross-site scripting attacks. Input
passed via the 'id' parameter to '/contenu_modifier.php' is not properly
sanitised before being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user's browser session in context of an
affected site.
Page : /contenu_modifier.php
Variables : id=[VulnHTTPCS]
Type : XSS
Method : GET
Solution :
References : https://www.httpcs.com/advisory/httpcs46
Credit : HTTPCS [Web Vulnerability Scanner]
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: