Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information.
Link | Tags |
---|---|
http://securitytracker.com/id?1017105 | vdb entry exploit |
http://www.securityfocus.com/bid/20673 | vdb entry |