Security Advisory
  • XSS vulnerability on easyAdmin2Pro Reported Date: 13-01-10
Rated Level: Critical
Impact: Cross Scripting,Locally Exploitable,Remotely Exploitable
Affected Software: easyAdmin2Pro
Description: The login form on easyAdmin2Pro is vulnerable to XSS injections. Login
page: http://www.site.com/easyadmin/index.php . The email field on this
page is not sanitized, so a user can put any script in here that they want.

----------------------------------------------------------------------------------
4. POC [Proof of Concept]:
----------------------------------------------------------------------------------
http://img69.imageshack.us/img69/9964/easyadminpoc.jpg

----------------------------------------------------------------------------------
5. Credits:
----------------------------------------------------------------------------------
Discovered by lossless from SecWorm Network

----------------------------------------------------------------------------------
6. Report Timeline:
----------------------------------------------------------------------------------
1/09/10 - lossless discovers vulnerability and notifies authors.
Further contact pending.


----------------------------------------------------------------------------------
7. About SecWorm Network:
----------------------------------------------------------------------------------
SecWorm Network is a group of Security Researchers & Ethical hackers with
the motto of security awareness and helping others to secure themselves.
Everyone can reach to us at http://www.SecWorm.net/


----------------------------------------------------------------------------------
8. Disclaimer & Copyright:
----------------------------------------------------------------------------------
The contents of this advisory are copyright � 2009 SecWorm Network, and may
be distributed freely provided that and proper credit is given.


Note: lossless
Solution: No Solution Till Date
References: http://secworm.net/
Feedback: If you have additional information or corrections for this security advisory please contact us at advisory(at)triviasecurity.org

Security Advisories by Month (2010)
Jul (3) Apr (5) Mar (3) Jan (8)
TS Promotion