Home / vulnerabilities piugame-multi.txt
Posted on 11 June 2008
Source : packetstormsecurity.org Link
Many bugs on CMS system Piugame
http://www.piugame.com
Researcher: Psymera
1.-Overview
Piugame CMS is one system used for control and contac of Pump It up
Gamers over the world and
Metod of control for official tournamets over the wold
2.-Description
This system has a vulnerabily as Sql Injection, Bypass credentials, XSS
and many others bugs
The system its too poor programed and not have a good method of control
on the variables has be sendend
Examples:
Script: club.piugame.com/list.html
SQL Injection:
Variable "stt" vulnerable
XSS:
Variables:
â??orderâ?
â??sttâ?
â??tbâ?
â??ss2â?
â??SCâ?
â??ss1â?
â??sst1â?
â??tbnameâ?
â??pageâ?
â??categoryâ?
â??keyâ?
â??keywordâ?
â??divpageâ?
Global Script: /home1/piuclub/public_html/_club/tempst_bbs/lib.php
SQL Injection:
variable: "community_no"
And of this form many others scripts has vulnerable for many other types
of attacks
4.- Disclosure Timeout
Vendor Contacted:
15-Marzo-2008 Vendor never response.
11-Abril-2008 Vendor never response.
24-Mayo-2008 Vendor never response.
Public Advisory: 10-Junio-2008
5.- Copyright
Researcher: Psymera
http://www.securitynation.com - Security Nation is a Lab Supported by
RISS Security Services.
http://www.riss.com.mx
Copyright SecurityNation.
Contact: psymera@gmail.com