AOH :: HP Unsorted A :: TB10707.HTM

Aardvark Topsites PHP Directory Disclosure Vulnerability



Aardvark Topsites PHP Directory Disclosure Vulnerability
Aardvark Topsites PHP Directory Disclosure Vulnerability



Aardvark Topsites PHP Directory Disclosure Vulnerability


Aardvark Topsites PHP is the premier free PHP/MySQL topsites script. An attacker can see what files are in the Directory. Knowing what is there to be executed can allow for more targeted and intelligent attacks against PHP Files known to be vulnerable listed there. A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.



Hackers Center Security Group (http://www.hackerscenter.com) 
Credit: Doz


Remote: YES
Class: Improper Instalation configuration.



Vendor: http://www.aardvarktopsitesphp.com 

Version: 5.1.2 and Previous versions!




* Attackers can exploit these issues via a web client.


Exploit:

http://www.site.com/topsites/sources/ 

http://www.site.com/sources/ 


Proff of Concept: http://i17.tinypic.com/646pvtg.jpg 



Security researcher? Join us: mail Zinho at zinho at hackerscenter.com

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.