[SECURITY] [3/5] Xomol CMS Local File Inclusion and SQL Injection


FS Owner
DNX has discovered some vulnerabilities in Xomol CMS, which can be exploited by malicious people to disclose potentially sensitive information or conduct SQL injection attacks.

This is a good example of why we should use magic quotes and filter chars from URLS

Checking user input is vital to not having your web page defaced by script kiddies who like milw0rm
The XSS security issue on Xomol CMS has been fixed since Xomol V.

Hello Programmers of the Wolrd

This is Juan Tepec, one of the main developers of Xomol CMS.
The XSS security issue has been fixed since Xomol V.
Thanks 2 u all for testing and helping us develop Xomol CMX.

Best Regards
Juan Tepec