Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Invision Power Board Privilege Esaclation (2.0.1 + more) Nov 04 2005 04:35PM
Anti Matter (antimatter gmail com)
---------
Title: Invision Power Board
---------
Version: 2.0.1 (maybe more)
---------
Severity: Low
---------
Info: Invision Board Admin able to execute arbitrary code as uid of
the apache process.
----------
Bug(s):

#1 Fails to jail location of Task Managers scripts and allows
directory traversal....

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus