header-logo
Suggest Exploit
vendor:
PHP Classifieds
by:
indoushka
7,5
CVSS
HIGH
E-mail Dump
N/A
CWE
Product Name: PHP Classifieds
Affected Version From: V6.09
Affected Version To: V6.09
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2009

PHP Classifieds V6.09 E-mail Dump Vulnerability

An attacker can exploit this vulnerability by accessing the dump.txt file located in the admin folder or the backup folder of the PHP Classifieds V6.09 application. This will allow the attacker to view the emails of all the users registered on the application.

Mitigation:

Ensure that the application is updated to the latest version and that all the security patches are applied.
Source

Exploit-DB raw data:

========================================================================================                  
| # Title    : PHP Classifieds V6.09 E-mail Dump Vulnerability           
| # Author   : indoushka                                                                                                              
| # Home     : www.dz-blackhat.com                                                                                                                                                                                                                   
| # Tested on: Lunix Français v.(9.4 Ubuntu)       
| # Bug      : E-mail Dump                                                             
======================      Exploit By indoushka       =================================
 # Exploit  : 
 
     1- http://127.0.0.1/phpclassifieds/admin/dump.txt
     
     2- http://127.0.0.1/phpclassifieds/admin/backup/
                    
Dz-Ghost Team ===== Saoucha * Star08 * Redda * Silitoad * XproratiX * onurozkan * n2n * ========================
Greetz : 
Exploit-db Team : 
(loneferret+Exploits+dookie2000ca)
all my friend :
His0k4 * Hussin-X * Rafik (www.Tinjah.com) * Yashar (www.sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
www.owned-m.com * Stake (www.v4-team.com) * r1z (www.sec-r1z.com) * D4NB4R http://www.ilegalintrusion.net/foro/
www.securityreason.com * www.m-y.cc * Cyb3r IntRue (avengers team) * www.alkrsan.net * www.mormoroth.net
--------------------------------------------------------------------------------------------------------------