ComGuar Posted September 8, 2012 Share Posted September 8, 2012 Hello people! I am testing CMS for vulnerabilities on the first place. If you find any error, please send message to me or post it here. If you have any idea how I can improve CMS it would be nice to say me Soon some components like forum and photo gallery will be added. Website URL: http://goo.gl/rDcS0 Verification file: http://goo.gl/X6UAF I created account for phpfreaks members, but I'll be happy if you register username: phpfreaks password: phpfreaks Thanks in advance! Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/ Share on other sites More sharing options...
darkfreaks Posted September 12, 2012 Share Posted September 12, 2012 Files listed in robots.txt but not linked Vulnerability description This file is listed in robots.txt but it's not linked anywhere in the site. Affected items /info The impact of this vulnerability Possible sensitive information disclosure. How to fix this vulnerability In robots.txt you should only include files or directories linked on the site. other than that you seem to be good. but i have been fooled before. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377169 Share on other sites More sharing options...
Coreye Posted September 12, 2012 Share Posted September 12, 2012 The message system is vulnerable to XSS attacks. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377178 Share on other sites More sharing options...
ComGuar Posted September 12, 2012 Author Share Posted September 12, 2012 Thanks guys! Fixed Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377193 Share on other sites More sharing options...
darkfreaks Posted September 12, 2012 Share Posted September 12, 2012 i don't think it is fixed it is still popping up JS alerts with session id. http://lmgtfy.com/?q=htmlpurifier+validation+php Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377301 Share on other sites More sharing options...
ComGuar Posted September 12, 2012 Author Share Posted September 12, 2012 Show me an example, crack it Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377308 Share on other sites More sharing options...
darkfreaks Posted September 12, 2012 Share Posted September 12, 2012 well first either FIX IT or remove the attak from your database so it can be retested. thank you. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377419 Share on other sites More sharing options...
ComGuar Posted September 12, 2012 Author Share Posted September 12, 2012 I cleaned all Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377422 Share on other sites More sharing options...
darkfreaks Posted September 12, 2012 Share Posted September 12, 2012 i could not recreate what coreye posted but i ran all the strings i could. they just came out as text. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377444 Share on other sites More sharing options...
ComGuar Posted September 12, 2012 Author Share Posted September 12, 2012 Yes, darkfreaks, there is no injection. Thanks Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377447 Share on other sites More sharing options...
darkfreaks Posted September 13, 2012 Share Posted September 13, 2012 @ComGuar: /info/ might not actually exist but according to your robots.txt file it is being disallowed. i checked manually instead of scanning. if it is not being actually used it will be indexed by crawlers even if it is disallowed. might want to take it off. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377494 Share on other sites More sharing options...
ComGuar Posted September 13, 2012 Author Share Posted September 13, 2012 Ok, but i disallowed all robots.txt: User-agent: * Disallow: / Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377510 Share on other sites More sharing options...
ComGuar Posted September 14, 2012 Author Share Posted September 14, 2012 I added some stuff Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377994 Share on other sites More sharing options...
Coreye Posted September 15, 2012 Share Posted September 15, 2012 The "Last post" on the forum is incorrect. The poster is correct, but the newest post doesn't have that subject. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378086 Share on other sites More sharing options...
ComGuar Posted September 15, 2012 Author Share Posted September 15, 2012 Fixed, thanks Coreye! Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378126 Share on other sites More sharing options...
darkfreaks Posted September 15, 2012 Share Posted September 15, 2012 http://goo.gl/robots.txt you still have /info/ in your robots.txt please remove it if it does not link to the site. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378144 Share on other sites More sharing options...
ComGuar Posted September 15, 2012 Author Share Posted September 15, 2012 Darkfreaks, this is not my robots.txt file! This file is hosted on goo.gl site. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378146 Share on other sites More sharing options...
darkfreaks Posted September 16, 2012 Share Posted September 16, 2012 so i was trying to figure out why it was picking up SQL injection on your site so i launched it visually and in your page i see this..... You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '2000'' at line 1 Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378395 Share on other sites More sharing options...
ComGuar Posted September 16, 2012 Author Share Posted September 16, 2012 Thanks Darkfreaks! Please tell me where on website you found error? I need to know file name and what you did when error happened. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378431 Share on other sites More sharing options...
darkfreaks Posted September 16, 2012 Share Posted September 16, 2012 not really sure what page it was but it had the link to the login and register page right above where the error was. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378462 Share on other sites More sharing options...
darkfreaks Posted September 17, 2012 Share Posted September 17, 2012 if i were you i would run my SQL statements through a syntax checker like MIME SQL or Yacker SQL. they usually tell you where your SQL has gone wrong syntax wise. i am pretty sure it is on your index.php page. since i know it is not login or register pages. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378615 Share on other sites More sharing options...
ComGuar Posted September 17, 2012 Author Share Posted September 17, 2012 It is server side, so you can't see syntax. In debug mode error reporting is error_reporting(E_ALL), and there is no error. Everything is working fine. I will try scripts you suggested. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378619 Share on other sites More sharing options...
darkfreaks Posted September 17, 2012 Share Posted September 17, 2012 also try making sure field|columns|tables are not MYSQL Reserved Words if they are they need to be enclosed with `backticks` and not 'single quotes' . Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378630 Share on other sites More sharing options...
ComGuar Posted September 17, 2012 Author Share Posted September 17, 2012 They are not, and every table have prefix. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378631 Share on other sites More sharing options...
darkfreaks Posted September 17, 2012 Share Posted September 17, 2012 can you post the code for your index(main) page so i can see where you are going wrong? and why it errors everytime the value 1 is inserted. Link to comment https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378632 Share on other sites More sharing options...
Recommended Posts