|
This vulnerability for the 'q', 'theme', 'language', 'tags', 'category', 'name', 'pageslinksby', 'itemsseperator', 'datetimetype', 'pageslinksby', 'itemsseperator', 'datetimetype' is only present when the magic_quotes_gpc PHP option is set to 'off'.
Successful exploitation via the 'tags' and 'category' parameters to index.php requires the 'q' parameter is set to "admin/modules/post/new" and the user has permission to create new posts.
Successful exploitation via the 'name' parameter to index.php requires 'q' is set to "admin/modules/form/elements" and the user has permission to edit form elements.
Successful exploitation via the 'pageslinksby', 'itemsseperator', and 'datetimetype' parameters to index.php requires 'q' is set to "admin/modules/page/options" and the user has permission to edit page options.
Successful exploitation via the 'numberofposts', 'numberofpages', 'showsummaryinfullview', 'postlinksby', 'itemsseperator', 'postsseperator', and 'datetimetype' parameters to index.php requires 'q' is set to "admin/modules/post/options" and the user has permission to edit post options.
Success exploitation via the 'content' parameter to index.php requires 'q' is set to "admin/modules/block/new" and the user has permission to create new blocks.
Successful exploitation via the 'name' parameter to index.php requires 'q' is set to "admin/modules/navigation" and the user has permission to create new navigation items.
Successful exploitation via the 'text' parameter to index.php requires 'q' is set to "admin/modules/page/new" and the user has permission to create new pages.
Successful exploitation via the 'summary' and 'text' parameters to index.php requires 'q' is set to "admin/modules/post/new" and the user has permission to create new posts.
|