Personal.Net Portal Multiple Vulnerabilities
This version of Personal.Net Portal(2.8.1) have Multiple Valnerabilities : User's Information Revelation, Upload a file with normal user that have low privilage, Persistent XSS for DDOS and remove Roles and ... (XSRF). With this path you can find User's Information of site: http://Example.com/Data/Statistics/Logins.xml. This Information includes: UserId, LoginCount, LastLogin, LoginName (for Example Admin), FirstName, LastName. After you logged in as a normal user (for example userName:user and Password:user), in the following path you can upload a specific file with POST Method which is containing user's cookie. http://Example.com/FCKeditor/editor/filemanager/connectors/aspx/connector.aspx?Command=FileUpload&Type=File&CurrentFolder=/