Remember yesterday’s Local File Disclosure bug? This one is in the same script– a script that serves up a given Javascript or CSS file, performing a few basic whitespace-removal and caching functions. As you saw yesterday, it can be used to read any given file, but it can also be used, through a different parameter, to include another file. This may include uploaded malware payloads, or just logfiles, which you poisoned with one of the log poisoning vulnerabilities I mentioned earlier.
/assets/minify.php?sb=../../../../../../var/www/error_log%00%0D%0Adfsa&type=bork&fsid=s
Posted by gawkerbugs