tobozo tagada

1 exploit Active since May 2002
CVE-2001-1334 EXPLOITDB text WRITEUP
PHPSlash 0.6.1 - Authenticated Arbitrary File Read via Block Source URL
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.