Skip to content

Upload File Lead To Remote code execution  #46

Description

Hello Sximo ,

My Name Is Mohamed Khaled Fathy [ Security Researcher ] From Egypt

I've found several serious security Vulnerability in Sximo CMS V3.1 Must Patching now .

1 - Cross Site Scripting Stored

About Cross Site Scripting :

Link : https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)

?Proof of concept :

1 - Go To Blog In [ http://sximobuilder.com/sximodemo/laravel/31/blog/read/new-from-our-blog ] 2 - In Comment Add XSS Payload [
3 - XSS Run [ Pop-Up ]

HTML Injection :

About HTML Injection : https://www.owasp.org/index.php/HTML_Injection

?Proof of concept :

1 - Go To Blog In [ http://sximobuilder.com/sximodemo/laravel/31/blog/read/new-from-our-blog ] 2 - Add HTML Code Like [

Matrix
3 - HTML Code Print

XSS Lead To Remote Code Execution

Please Check This Link : https://oreoshake.github.io/xss/rce/bugbounty/2015/09/08/xss-to-rce.html

Thanks And Please Email Me [ Sirmatrixpage@gmail.com ]

XSS Payload : ">

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions