vendor:
QuickerSite
by:
AmnPardaz Security Research Team
7.5
CVSS
HIGH
Insecure Direct Object Reference, Failure to Restrict URL Access, Cross Site Scripting (XSS)
639, 285, 79
CWE
Product Name: QuickerSite
Affected Version From: 1.8.2005
Affected Version To: 1.8.2005
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
N/A
QuickerSite Multiple Vulnerabilities
Everyone can change admin password, edit all the site info., such as admin email address, edit all the site design, mailbomb others, Reflected XSS attack by circumventing the ASP.Net XSS denier (Path disclosure on the open error mode), Redirect Reflected XSS Attack In 'SB_redirect' parameter, Content Sender Spoofing, Mailbombing.
Mitigation:
N/A