CVE-2009-0966 Information
Description
PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
Reference
http://osvdb.org/52789 http://secunia.com/advisories/34325 http://www.securityfocus.com/bid/34157 https://exchange.xforce.ibmcloud.com/vulnerabilities/49302 https://www.exploit-db.com/exploits/8230 PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
Share on: