[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

xrms 1.99.2 (RFI/XSS/IG) Multiple Remote Vulnerabilities

Author
AzzCoder
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3446
Category
web applications
Date add
24-07-2008
Platform
unsorted
========================================================
xrms 1.99.2 (RFI/XSS/IG) Multiple Remote Vulnerabilities
========================================================



##############################################################

XMRS Multiple Vulnerabilities (ZeroDay at 25-07-2008)
Author: AzzCoder
Product: http://www.xrms.org/
Product Type: CRM
Thanks: coresecurity.com

Remote File Inclusion
	File: activities/workflow-activities.php
	Variable: $include_directory
	Required register_globals: Yes

XSS
	Multiple Files
	Variable: $msg
	Quote limitations: Yes

Information Gathering
	tests/info.php
	phpinfo() call

##############################################################



#  0day.today [2024-07-08]  #