TxxCMS_Multiple File inclusion Vulnerabilies

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1052894 漏洞类型
发布时间 2007-09-12 更新时间 2007-09-12
CVE编号 CVE-2007-4819
CVE-2007-4818
CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2007090033
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
:::::::::::::::::::::::::::::::::::::::::::::::::::.....................
..
::|  | (_)          |  | |                       / ____|                  
::|  | |_  ___ ___  |  | | __ _ _ __ ___   ___  | |     _ __ _____      __
::| . ` | |/ __/ _  | . ` |/ _` | '_ ` _  / _  | |    | '__/ _   / / /
::| |  | | (_|  __/ | |  | (_| | | | | | |  __/ | |____| | |  __/ V  V / 
::|_| _|_|______| |_| _|__,_|_| |_| |_|___|  _____|_|  ___| _/_/
:::::::::::::::::::::::::::::We got the nicest name in the security scene!
::::::::Info::.
::Script: Txx CMS
::Homepage:https://sourceforge.net/projects/txx/
::
:::::::::Details::.
::Type: File_Inclusion
::
::in modules/addons/plugin.php
::and modules/addons/sidebar.php
::and modules/mail/index.php
::and modules/mail/mailbox.php
::
::$doc_root is not defined
:: 
::
:: we also found countless xss in there
:: but we wont list em because we got more important 
:: stuff to do  
::::::::::::::::::::::::::::::::.
:::::::::::Additional_Information::.
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.
::Contact: nne (at) chilloutzone (dot) eu [email concealed]
::Website: http://nnc.unkn0wn.eu or http://www.chilloutzone.eu
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.