Full Disclosure mailing list archives
SSD Advisory – PHP Melody Multiple Vulnerabilities
From: Maor Shwartz <maors () beyondsecurity com>
Date: Mon, 9 Oct 2017 16:16:52 +0300
SSD Advisory – PHP Melody Multiple Vulnerabilities Full report: https://blogs.securiteam.com/index.php/archives/3464 Twitter: @SecuriTeam_SSD Weibo: SecuriTeam_SSD Vulnerabilities Summary The following advisory describes three (3) vulnerabilities found in PHP Melody version 2.7.3. PHP Melody is a “self-hosted Video CMS which evolved over the last 9 years. SEO optimization, unbeaten security and speed are advantages you no longer have to compromise on. A truly great CMS should help you save time and make your life easier not complicate it. Nobody enjoys spending time and money on inferior solutions. If you value your time, don’t settle for anything but the best video CMS with a proven track record, constant support and updates.” The vulnerabilities found in PHP Melody are: Stored PreAuth XSS that leads to administrator account takeover SQL Injection (1) SQL Injection (2) Credit An independent security researcher, Paulos Yibelo, has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program. -- Thanks Maor Shwartz Beyond Security GPG Key ID: 93CC36E2DE7FF514
Attachment:
SSD Advisory – PHP Melody Multiple Vulnerabilities – SecuriTeam Blogs.pdf
Description:
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- SSD Advisory – PHP Melody Multiple Vulnerabilities Maor Shwartz (Oct 10)