Download Firefox: WindowsMac OS X
logo       
Google Custom Search
    AddThis Social Bookmark Button

Re: Simple PHP scanning ..: msg#00024

Subject: Re: Simple PHP scanning ..
Ulf Harnhammar wrote:
> include("templatedir/$file");

with this you can do

file=../../../../../../../../../../../../../etc/passwd

directory traversal and get any (readable) file from the server.

Not the same vulnerability, but a vulnerability :)

Bye
 Gerardo


<Prev in Thread] Current Thread [Next in Thread>