|
product :Speedwiki 2.0
vendor site: http://speedywiki.sourceforge.net/
risk:critical
a user logged in , can upload a PHP script on the server , by the upload script , there's actually no upload filter on this cms
path : /speedywiki/index.php?upload=1
xss get :
/index.php?showRevisions='">
full path disclosure :
/speedywiki/index.php?showRevisions[]/speedywiki/index.php?searchText[]/speedywiki/upload.php
laurent gaffi=E9 & benjamin moss=E9
http://s-a-p.ca/
contact: saps.audit@gmail.com