[] NeoSense

XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering

Author: AzzCoder
type: webapps
platform: php
port: 
date_added: 2008-07-24 
date_updated: 2016-12-21 
verified: 1 
codes: OSVDB-47245;CVE-2008-3400;OSVDB-47168;CVE-2008-3399;OSVDB-47167;CVE-2008-3398 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comxrms-2006-07-25-v1.99.2-.tar.gz

##############################################################

XMRS Multiple Vulnerabilities (ZeroDay at 25-07-2008)
Author: AzzCoder [azzcoder@hotmail.com]
Product: http://www.xrms.org/
Product Type: CRM
Thanks: coresecurity.com

Remote File Inclusion
	File: activities/workflow-activities.php
	Variable: $include_directory
	Required register_globals: Yes

XSS
	Multiple Files
	Variable: $msg
	Quote limitations: Yes

Information Gathering
	tests/info.php
	phpinfo() call

##############################################################

# milw0rm.com [2008-07-25]