This document details SQL injection and multiple XSS vulnerabilities in web@all CMS 2.0, including affected parameters, attack vectors, and proof-of-concept HTTP requests. It provides technical analysis of input sanitization failures and exploitation methods.
Classification
Writeup 95%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target:web@all CMS 2.0
No auth needed
Prerequisites:Access to the vulnerable web application