cve/2007/CVE-2007-6652.md
2024-05-26 14:27:05 +02:00

781 B

CVE-2007-6652

Description

cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to index.php, which writes to dati/generali/footer.dtb (aka the XCMS footer).

POC

Reference

Github

No PoCs found on GitHub currently.