[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Pluck 4.7 multiple vulnerabilities

Author
Bl4k3
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-16915
Category
web applications
Date add
07-09-2011
Platform
php
# Exploit Title: Pluck 4.7 multiple vulnerabilities
 
# Google Dork: Powered by pluck
 
# Date: 05/08/2011
 
# Author: Bl4k3
 
# Software Link: http://www.pluck-cms.org/?file=download
 
# Version: 4.7
 
# Tested on: Debian
 
# CVE : /
 
1-File Inclusion:
 
include(ALBUMS_DIR.'/'.$_GET['album'].'.php');
 
Require:
 
if (file_exists(ALBUMS_DIR.'/'.$_GET['album'].'.php')) {
function albums_pages_site() {
 
2-File Inclusion
 
include (ALBUMS_DIR.'/'.$album['seoname'].'.php');
foreach ($albums as $album) {
$albums  = albums_get_albums();
 
3-File Disclosure
 
echo readfile('../../settings/modules/albums/'.$image);
$image = $_GET['image'];
 
requires:
 
if (file_exists('../../settings/modules/albums/'.$image)) {
 
And a lot of low vulnerabilities!!
 
 
Bl4k3 HardC0de



#  0day.today [2024-11-15]  #