OneFileCMS - Failure to Restrict URL Access

EDB-ID: 18632 CVE: N/A OSVDB-ID: 80553
Verified: Author: Abhi M Balakrishnan Published: 2012-03-20
Download Exploit: Source Raw Download Vulnerable App: N/A
# Exploit Title: OneFileCMS - Failure to Restrict URL Access
# Date: 12th March 2012
# Author: Abhi M Balakrishnan
# Software Link:
# Version: upto 1.1.4
# Tested on: Apache-2.2.17, PHP-5.2.17, MySQL-5.5.9, Windows 6.2
# Vulnerability Status: Fixed on version 1.1.5.	Developer was very quick in responding to mails and to fix the issue. Bugfix version released within minutes after the notification. Great work.!!!

# Vulnerability: Failure to Restrict URL Access, since the redirection mechanism can be bypassed easily

# Exploit:

	Step 1:	Create a rule in No-Redirect Add-on: ^
	Step 2:	Access

# PoC Video: