Cafelog b2 B2Functions Script B2INC Variable Include Vulnerability

A remote file include vulnerability has been reported in Cafelog b2. Due to insufficient sanitization of user-supplied values by the b2functions.php script, it is possible for a remote attacker to influence the location of included files. This could result in execution of malicious PHP code.


 

Privacy Statement
Copyright 2010, SecurityFocus