------ NOCC Webmail <= 1.0 multiple arbitrary local inclusion + ---------------- php injection -> remote code execution / / cross site scripting / path disclosure -------------------------------------------------------------------------------- software: site: http://nocc.sourceforge.net/ description: "NOCC is a webmail client written in PHP. It provides webmail access to IMAP and POP3 accounts." -------------------------------------------------------------------------------- i) vulnerable code in html/footer.php at lines 2-11: ...