========================================================================
| # Title : impresscms-1.3.9 Open Redirect vulnerability
| # Author : indoushka
| # email : indoushka4ever@gmail.com
| # Tested on : windows 8.1 Français V.(Pro)
| # Version : 1.3.9
| # Vendor : http://www.impresscms.org/
| # Dork : Powered by ImpressCMS
========================================================================
poc :
Impress CMS is susceptible to URL direction attack.
When a malicious user sends a payload as "http://localhost/user.php?xoops_redirect="maliciouslink"", user
enters the credentials and gets redirected to the malicious link.
Payload - http://localhost/user.php?xoops_redirect="malicious link or port number"
Greetz : ⵏⴻⴽⴽⴰⴰ ⵙⴰⵍⴰⵀ ⴻⴷⴷⵉⵏⴻ------ⵯⵉⵯⴰ ⴰⵎⴰⵣⵉⴳⴻⵏ-------- ⵎⴰⵅⵡⴻⵍⵍ ⵛⴰⵛⵀⴷoⵍⵍⴰⵔ ------
|
jericho * Larry W. Cashdollar * moncet-1 * achraf.tn |
|
===================== pⴰⵛⴽⴻⵜ ⵙⵜoⵔⵎ ⵙⴻⵛⵓⵔⵉⵜⵢ =============================