Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15441
HistoryDec 20, 2006 - 12:00 a.m.

MkPortal Urlobox Cross Site Request Forgery

2006-12-2000:00:00
vulners.com
21

MkPortal Urlobox Cross Site Request Forgery

Discovered by: Demential
Web: http://www.burnhead.it
E-mail: [email protected]
Mkportal website: http://www.mkportal.it

posting [img]?ind=urlobox&op=delete&idurlo=X[/img] in MkPortal urlobox
where X is an ID of a message,
when administrator opens urlobox page
message X will be erased.


Email.it, the professional e-mail, gratis per te: http://www.email.it/f

Sponsor:
Stupisci i tuoi Amici con le Fantastiche Idee Regalo D-Mail !
Clicca qui: http://adv.email.it/cgi-bin/foclick.cgi?mid=5889&d=20061220