Jeebles Technology Jeebles Directory 2.9.60 - 'download.php' Local File Inclusion
Author: hack2prison
type: webapps
platform: php
port:
date_added: 2007-10-22
date_updated: 2014-01-05
verified: 1
codes: CVE-2007-5706;OSVDB-41869
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/26171/info
Jeebles Directory is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to execute local scripts or to view arbitrary files that may contain sensitive information that can aid in further attacks.
This issue affects Jeebles Directory 2.9.60; other versions may also be affected.
http://www.example.com/[path]/download.php?settings2.inc.php