exploit-db-mirror/platforms/php/webapps/26668.txt
Offensive Security 5e2fc10125 DB: 2016-09-03
2016-09-03 13:13:25 +00:00

12 lines
No EOL
559 B
Text
Executable file

source: http://www.securityfocus.com/bid/15651/info
phpAlbum is prone to a local file-include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the webserver process.
Note that this issue may also be leveraged to read arbitrary files on an affected computer with the privileges of the webserver.
phpAlbum 0.2.3 and prior versions are vulnerable.
http://www.example.com/main.php?cmd=../
http://www.example.com/main.php?cmd=album&var1=../