← Advisories

Pointter PHP Content Management System 1.2 Multiple Vulnerabilities

Medium
Advisory ID
ZSL-2011-5002
Release Date
16 March 2011
Vendor
PangramSoft GmbH - http://www.pointter.com
Affected Version
1.2
CVE
N/A
Tested On
Microsoft Windows XP Professional SP3 (EN), Apache 2.2.14 (Win32), PHP 5.3.1, MySQL 5.1.41
Summary

Pointter PHP Content Management System is an advanced, fast and user friendly CMS script that can be used to build simple websites or professional websites with product categorization, product blogs, member login and search modules. The webmaster can create unlimited static page boxes, static pages, main categories, sub categories and product pages.

Description

Pointter CMS suffers from multiple vulnerabilities (post-auth) including: Stored XSS, bSQLi, LFI, Cookie Manipulation, DoS.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
16.03.2011Initial release
17.03.2011Added reference [4], [5], [6], [7] and [8]
22.03.2011Added reference [9], [10], [11], [12], [13], [14] and [15]