This exploit demonstrates XSS and remote file access vulnerabilities in WD-CMS 3.0. The XSS is triggered via the 'mode' parameter, while the file access flaw allows reading arbitrary files by manipulating the same parameter.
Classification
Working Poc 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target:WD-CMS 3.0
No auth needed
Prerequisites:access to the target web application