CompactCMS 1.4.0 (tiny_mce) Remote File Upload
Posted on 15 May 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>CompactCMS 1.4.0 (tiny_mce) Remote File Upload</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>============================================== CompactCMS 1.4.0 (tiny_mce) Remote File Upload ============================================== ########################################################## #Title: CompactCMS 1.4.0 (tiny_mce) Remote File Upload #Vendor: http://www.compactcms.nl/ ########################################################## #AUTHOR: ITSecTeam #Email: Bug@ITSecTeam.com #Website: http://www.itsecteam.com #Forum : http://forum.ITSecTeam.com #Original Advisory: www.ITSecTeam.com/en/vulnerabilities/vulnerability52.htm #Thanks: r3dm0v3, pejvak, am!rkh@n ########################################################## #DESCRIPTION (by vendor):################################# CompactCMS might just be the tenth CMS you considered using for your website. If that's true, ask yourself why you haven't found the right Content Management System just yet. CompactCMS is light-weight, truly efficient and fully Ajax loaded. #POC:##################################################### http://site.com/admin/includes/tiny_mce/plugins/ tinybrowser/upload.php # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-05-15]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>