Skip to content

imageDownload.php is a security risk #1

Description

@ncarver

Reported by sean.merrigan [at] tubemogul.com, Dec 17, 2013
This file can allow users to download any file from the php server it's running on.

  1. Go to [path to the file on your server]/imageDownload.php?imageUrl=/etc/hosts (or some other system file)
  2. Open the downloaded file in a text editor
  3. Look at the contents of the file you've been able to obtain from outside of webroot.

I'm not sure what to expect from this file, as it looks like it's trying to download a file from the host rather than from the ad.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions