========================================================================
| # Title : Seditio CMS version 1.7.5 HTML Injection vulnerability
| # Author : indoushka
| # email : indoushka4ever@gmail.com
| # Tested on : windows 8.1 Français V.(Pro)
| # Version : 1.7.5
| # Vendor : http://www.seditiocms.com
| # Dork : "Powered by Seditio"
========================================================================
poc :
register On Website go to list.php?c=news add new post
http://127.0.0.1/1-44cd2b-seditio-175/Seditio-175/page.php?m=edit&id=9&r=list
inject any html code and on condition use Parsing:Html
Greetz : ⵏⴻⴽⴽⴰⴰ ⵙⴰⵍⴰⵀ ⴻⴷⴷⵉⵏⴻ------ⵯⵉⵯⴰ ⴰⵎⴰⵣⵉⴳⴻⵏ-------- ⵎⴰⵅⵡⴻⵍⵍ ⵛⴰⵛⵀⴷoⵍⵍⴰⵔ ------
|
jericho * Larry W. Cashdollar * moncet-1 * achraf.tn |
|
===================== pⴰⵛⴽⴻⵜ ⵙⵜoⵔⵎ ⵙⴻⵛⵓⵔⵉⵜⵢ =============================