ReloadCMS 1.2.5 - 'index.php' Local File Inclusion

EDB-ID:

30697


Author:

sekuru

Type:

webapps


Platform:

PHP

Date:

2007-10-20


source: https://www.securityfocus.com/bid/26143/info

ReloadCMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this issue may allow an unauthorized user to execute local scripts or to view arbitrary files that may contain sensitive information that can aid in further attacks. 

http://www.example.com/index.php?module=../../../../etc/passwd