lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20080725151303.20664.qmail@securityfocus.com> Date: 25 Jul 2008 15:13:03 -0000 From: azzcoder@...mail.com To: bugtraq@...urityfocus.com Subject: XRMS 1.99.2 (RFI/XSS/IG) Multiple Remote Vulnerabilities ############################################################## XMRS Multiple Vulnerabilities (ZeroDay at 25-07-2008) Author: AzzCoder [azzcoder@...mail.com] Product: http://www.xrms.org/ Product Type: CRM Thanks: coresecurity.com Remote File Inclusion File: activities/workflow-activities.php Variable: $include_directory Required register_globals: Yes XSS Multiple Files Variable: $msg Quote limitations: Yes Information Gathering tests/info.php phpinfo() call ############################################################## # milw0rm.com [2008-07-25]