Jump to content

Recommended Posts

Hello!

 

I have spent the last several weeks working on a content management system for a first year university project.

 

I'm quite happy with where its at and I'd really appreciate if you could have a quick look for security issues.

http://cs1.ucc.ie/~jct1/cs1109/lab18

 

The site itself is backed by my cms and just contains a guide on how to use the backend.

 

Proof of ownership: http://cs1.ucc.ie/~jct1/cs1109/lab18/phpfreaks.txt

 

Thanks in advance!

James

 

Link to comment
https://forums.phpfreaks.com/topic/232042-is-my-cms-secure/
Share on other sites

  • 3 weeks later...

Your CMS has heaps of security issues. Without much effort I was able to obtain admin access. A few issues include:

 

  • Cross Site Request Forgeries
  • SQL Injection
  • Weak account policies

 

msg me if you want full details.

 

proof: http://cs1.ucc.ie/~jct1/cs1109/lab18/index.php?article_id=80 (check the sourcecode)

 

Link to comment
https://forums.phpfreaks.com/topic/232042-is-my-cms-secure/#findComment-1201381
Share on other sites

  • 1 month later...
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.