Posted by Patrick Webster via Fulldisclosure on Apr 04
Date:
04-Apr-2017
Product:
AcoraCMS
Versions affected:
7.0.0.6 (known bugs from 6.0.6 are still present
http://www.digitalsec.net/stuff/explt+advs/CM3.AcoraCMS.v6.txt).
Vulnerabilities:
1) Arbitrary browser redirect:
POST /forums/login.asp HTTP/1.1
Host: [target]
Content-Type: application/x-www-form-urlencoded
Content-Length: 70…