XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
Author: AzzCoder
type: webapps
platform: php
port:
date_added: 2008-07-24
date_updated: 2016-12-21
verified: 1
codes: OSVDB-47245;CVE-2008-3400;OSVDB-47168;CVE-2008-3399;OSVDB-47167;CVE-2008-3398
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comxrms-2006-07-25-v1.99.2-.tar.gz
##############################################################
XMRS Multiple Vulnerabilities (ZeroDay at 25-07-2008)
Author: AzzCoder [azzcoder@hotmail.com]
Product: http://www.xrms.org/
Product Type: CRM
Thanks: coresecurity.com
Remote File Inclusion
File: activities/workflow-activities.php
Variable: $include_directory
Required register_globals: Yes
XSS
Multiple Files
Variable: $msg
Quote limitations: Yes
Information Gathering
tests/info.php
phpinfo() call
##############################################################
# milw0rm.com [2008-07-25]