p30vel eBook Store 'login.php' File Disclosure Vulnerability
BID:40552
Info
p30vel eBook Store 'login.php' File Disclosure Vulnerability
| Bugtraq ID: | 40552 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2010 12:00AM |
| Updated: | Jun 02 2010 12:00AM |
| Credit: | indoushka |
| Vulnerable: |
P30vel eBook Store 0 |
| Not Vulnerable: | |
Discussion
p30vel eBook Store 'login.php' File Disclosure Vulnerability
p30vel eBook Store is prone to a file-disclosure vulnerability.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on a computer running the vulnerable application. This may aid in further attacks.
p30vel eBook Store is prone to a file-disclosure vulnerability.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on a computer running the vulnerable application. This may aid in further attacks.
Exploit / POC
p30vel eBook Store 'login.php' File Disclosure Vulnerability
Attackers may exploit this issue through a browser.
The following example URI is available:
http://www.example.com/admin/file_manager.php/login.php?action=download&filename=/includes/configure.php
Attackers may exploit this issue through a browser.
The following example URI is available:
http://www.example.com/admin/file_manager.php/login.php?action=download&filename=/includes/configure.php
Solution / Fix
p30vel eBook Store 'login.php' File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
p30vel eBook Store 'login.php' File Disclosure Vulnerability
References:
References:
- eBook Store Homepage (p30vel)