what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

major_rls17.txt

major_rls17.txt
Posted Jun 15, 2006
Authored by David "Aesthetico" Vieira-Kurz | Site majorsecurity.de

SixCMS versions 6 and below suffer from cross site scripting and directory traversal vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 86aea3765b602c514f871245245d4951c1218ff5a8916614b44e8a91ac8aa268

major_rls17.txt

Change Mirror Download
[MajorSecurity #17] SixCMS <= 6 - Multiple XSS and directory traversal vulnerabilities
----------------------------------------------

Software: SixCMS

Version: <=6

Type: Cross site scripting

Date: June, 12th 2006

Vendor: Six Offene Systeme GmbH

Page: http://www.sixcms.de


Credits:
----------------------------------------------

Discovered by: David "Aesthetico" Vieira-Kurz
http://www.majorsecurity.de

Original Advisory:
----------------------------------------------
http://www.majorsecurity.de/advisory/major_rls17.txt

Affected Products:
----------------------------------------------

SixCMS 6 and prior

Description:
----------------------------------------------

SixCMS is a well known and commercial enterprise Content Management System.

Requirements:
----------------------------------------------

register_globals = On

Vulnerability:
----------------------------------------------

Input passed to the "template" parameter in "detail.php" is not
properly verified, before it is used to execute the given arguments.

Acquiring access to known files outside of the web root and current directory
is possible through directory traversal techniques.
This is made possible through the use of "../../" in a HTTP request.

Input passes to the "page" parameter in "list.php" is not properly sanitised,
before it is used to execute the given arguments.
This can be exploited to execute arbitrary HTML and script code in context of an affected site.


Solution:
----------------------------------------------
Edit the source code to ensure that input is properly sanitised.
You should work with "htmlspecialchars()" or "strip_tags()" php-function to ensure that html tags
are not going to be executed.

Example:
<?php
echo htmlspecialchars("<script");
?>

Set "register_globals" to "Off".

Examples:
----------------------------------------------
/detail.php?template=../../../../../../etc/passwd%00
/list.php?page=<script>alert("MajorSecurity")</script>

Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close