vendor:
FineCMS
by:
sohaip-hackerDZ
8,8
CVSS
HIGH
Reflected XSS, Arbitrary File Modify, Authenticated SQL Injection
89, 22, 89
CWE
Product Name: FineCMS
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:mvc.net.pl:finecms:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2017
FineCMS 1.0 Multiple Vulnerabilities
file /application/lib/ajax/get_image.php the $_POST['id'] and $_POST['name'] and $_GET['folder'] without any validated, sanitised or output encoded. The base function for modify the template can modify the filename,this leads to the Arbitrary File Modify, who could allow attacker getshell. All FineCMS use PDO to connect the mysql server, so all the data without any validated, sanitised or output encoded injection database.but in application/core/controller/excludes.php, the website author use mysqli to connect mysql server.the lead SQL injection, who could allow attacker use some payload to get data in database.
Mitigation:
Validate, sanitize and output encode user input, use PDO to connect the mysql server, use parameterized queries.