Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-0996 PoC — 11in1 跨站请求伪造漏洞和本地文件包含漏洞

Source
Associated Vulnerability
Title:11in1 跨站请求伪造漏洞和本地文件包含漏洞 (CVE-2012-0996)
Description:11in1中存在跨站请求伪造漏洞和本地文件包含漏洞。攻击者可利用这些漏洞在受影响站点上下文的不知情用户浏览器上执行任意脚本代码,盗取基于cookie的认证证书,在受影响应用程序上下文中打开或运行任意文件。11in1 1.2.1版本中存在这些漏洞,其它版本也可能受到影响。
Description
Multiple directory traversal vulnerabilities in 11in1 1.2.1 stable 12-31-2011 allow remote attackers to read arbitrary files via a .. (dot dot) in the class parameter to (1) index.php or (2) admin/index.php.
File Snapshot

id: CVE-2012-0996 info: name: 11in1 CMS 1.2.1 - Local File Inclusion (LFI) author: daffainfo ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.