URL: http://www.exploit-db.com/exploits/18055/ Researcher: longrifle0x The researcher blames "ajax.php" but there is no ajax.php in the distribution, nor is there any mention of ajax anywhere, and there is limited usage of an "id" parameter. - Steve