source: https://www.securityfocus.com/bid/64740/info EZGenerator is prone to a local file-disclosure vulnerability and a cross-site request-forgery vulnerability. An attacker may leverage these issues to perform unauthorized actions in the context of a logged-in user, or obtain sensitive information from local files on computers running the vulnerable application. This may aid in further attacks. Local File Disclosure: ===================== www.example.com/utils.php?action=download&filename=file.php%00 CSRF [Add Admin]: ================