LFI to RCE via access_log injection

Linkarity SQL Injection and XSS Vuln


[o] Linkarity SQL Injection and XSS Vulnerability

Software : Linkarity
Vendor : http://www.linkarity.com/
Author : NoGe


[o] Vulnerable file
links.php


[o] Exploit
http://localhost/[path]/links.php?cat_id=[SQL] & [XSS]


[o] Dork
"Powered by Linkarity"


Comments