.. / CVE-2012-0996

Exploit for 11in1 CMS 1.2.1 - Local File Inclusion (LFI) (CVE-2012-0996)

Description:

Multiple directory traversal vulnerabilities in 11in1 1.2.1 stable 12-31-2011 allow remote attackers to read arbitrary files via a .. (dot dot) in the class parameter to (1) index.php or (2) admin/index.php.

Nuclei Template

View the template here CVE-2012-0996.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2012/CVE-2012-0996.yaml
Copy

References:

https://www.htbridge.ch/advisory/HTB23071
https://github.com/ARPSyndicate/kenzer-templates
https://www.exploit-db.com/exploits/36784
https://nvd.nist.gov/vuln/detail/CVE-2012-0996