actSite BASE.PHP BASECFG[BASEDIR] Parameter Remote File Include Vulnerability

An attacker can exploit these issues via a browser.

The following proof-of-concept URI is available:

http://www.example.com/lib/base.php?BaseCfg[BaseDir]=[ Evil Code ]


 

Privacy Statement
Copyright 2010, SecurityFocus