Bugtraq mailing list archives

Re: PHPNuke viewpage.php allows Remote File retrieving


From: Tonu Samuel <tonu () please do not remove this spam ee>
Date: 26 Mar 2003 09:26:08 +0200

On Tue, 2003-03-25 at 21:28, Jim Geovedi wrote:
On Tue, 25 Mar 2003 11:59:26 -0600 DaiTengu wrote:
viewpage.php is a part of PHPNuke.
The Script allows an attacker to view all files on the System.

Example:

http://server.com/viewpage.php?file=/etc/passwd

Not repeatable with 6.0

  Tõnu


Current thread: