SZEWO PhpCommander Download.PHP Local File Include Vulnerability

PhpCommander is prone to a local file-include vulnerability because the application fails to sufficiently sanitize user supplied-input. This issue may allow an attacker to obtain sensitive data and to execute arbitrary local script code in the context of the application.

Version 3.0 is vulnerable to this issue; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus