islam cms 1.0 PHP code injection Vulnerability

2018.03.03
dz indoushka (DZ) dz
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

| # Title : islam cms 1.0 PHP code injection Vulnerability | # Author : indoushka | # email : indoushka4ever@gmail.com | # Tested on: windows 8.1 Fran├žais V.(Pro) | # Vendor : http://almohtaref.net/islamcms_1.0.zip ============================================================= PHP code injection : This script is vulnerable to PHP code injection. PHP code injection is a vulnerability that allows an attacker to inject custom code into the server side scripting engine. This vulnerability occurs when an attacker can control all or part of an input string that is fed into an eval() function call. Eval will execute the argument as code. This vulnerability affects /islamcms/index.php poc : In the search box use payload : http://127.0.0.1/islamcms/index.php?name=search ${@system(dir)} ${@print inoushka} word=%24%7b%40print indoushka}%7d Greetz : jericho http://attrition.org & http://www.osvdb.org/ * http://packetstormsecurity.com * http://is-sec.org/cc/ Hussin-X *D4NB4R * ViRuS_Ra3cH * yasMouh * https://www.corelan.be * Larry W. Cashdollar* ---------------------------------------------------------------------------------------------------------------


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2018, cxsecurity.com

 

Back to Top