Jump to content

Recommended Posts

Hello people!

 

I am testing CMS for vulnerabilities on the first place.

If you find any error, please send message to me or post it here. If you have any idea how I can improve CMS it would be nice to say me :)

Soon some components like forum and photo gallery will be added.

 

Website URL: http://goo.gl/rDcS0

Verification file: http://goo.gl/X6UAF

 

 

I created account for phpfreaks members, but I'll be happy if you register :)

 

username: phpfreaks

password: phpfreaks

 

 

Thanks in advance!

Link to comment
https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/
Share on other sites

Files listed in robots.txt but not linked

Vulnerability description

This file is listed in robots.txt but it's not linked anywhere in the site.

Affected items

/info

The impact of this vulnerability

Possible sensitive information disclosure.

How to fix this vulnerability

In robots.txt you should only include files or directories linked on the site.

 

other than that you seem to be good. but i have been fooled before. ;)

Link to comment
https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377169
Share on other sites

@ComGuar: /info/ might not actually exist but according to your robots.txt file it is being disallowed. i checked manually instead of scanning. if it is not being  actually used it will be indexed by crawlers even if it is disallowed. might want to take it off.

Link to comment
https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1377494
Share on other sites

so i was trying to figure out why it was picking up SQL injection on your site so i launched it visually  and in your page i see this..... :wtf:

 

 

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '2000'' at line 1

 

 

Link to comment
https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378395
Share on other sites

if i were you i would run my SQL statements through a syntax checker like MIME SQL or Yacker SQL.

 

they usually tell you where your SQL has gone wrong syntax wise.

 

i am pretty sure it is on your index.php page. since i know it is not login or register pages.

 

 

Link to comment
https://forums.phpfreaks.com/topic/268163-v-cms-beta-test/#findComment-1378615
Share on other sites

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.