____________________ ___ ___ ________ \_ _____/\_ ___ \ / | \\_____ \ | __)_ / \ \// ~ \/ | \ | \\ \___\ Y / | \ /_______ / \______ /\___|_ /\_______ / \/ \/ \/ \/ .OR.ID ECHO_ADV_58$2006 ----------------------------------------------------------------------------------------------- [ECHO_ADV_58$2006]Cyberfolio <=2.0 RC1 $av Remote File Inclusion Vulnerability ----------------------------------------------------------------------------------------------- Author : Dedi Dwianto a.k.a the_day Date Found : November, 01nd 2006 Location : Indonesia, Jakarta web : http://advisories.echo.or.id/adv/adv58-theday-2006.txt Critical Lvl : Highly critical Impact : System access Where : From Remote --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~ Application : Cyberfolio version : <=2.0 RC1 URL : http://www.cyberfolio.org --------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~~~~ I found vulnerability in script view.php --------------------------view.php----------------------------------- ....