cve/2007/CVE-2007-6652.md
2025-09-29 21:09:30 +02:00

792 B

CVE-2007-6652

Description

cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to index.php, which writes to dati/generali/footer.dtb (aka the XCMS footer).

POC

Reference

Github

No PoCs found on GitHub currently.