vendor:
PHP Hosting Directory
by:
ZoRLu
7,5
CVSS
HIGH
Database Disclosure
200
CWE
Product Name: PHP Hosting Directory
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Professional sp3
2010
PHP Hosting Directory 2.0 Database Disclosure Exploit (.py)
This exploit allows an attacker to download the database of a vulnerable PHP Hosting Directory 2.0 website. The attacker needs to provide the URL of the vulnerable website and the date of the backup file they want to download. The exploit then downloads the backup file to the local system.
Mitigation:
Ensure that the backup files are not accessible from the web server.