Name : XCMS <= v1.83 Remote Command Execution Vulnerability Author : x0kster Email : x0kster@gmail.com Site : ihteam.net Script Download : http://www.xcms.it Date : 28/12/2007 Dork : inurl:"mod=notizie" The xcms's footer(that is in "/dati/generali/footer.dtb") is included in each page of the xcms. Taking "home.php" for example: So the xcms allow you to modify the footer throught a bugged page called cpie.php included in the admin panel. So let's take a look to the bugged code. So with a simple html form we can change the footer. Ex: