Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: FreeForum 0.9.0 <=- (index.php fpath) Remote File Include Vulnerability Jan 24 2007 10:13AM
Stefano Zanero (s zanero securenetwork it)
> FreeForum 0.9.0 <=- (index.php fpath) Remote File Include Vulnerability

Bogus. You really don't know what you are doing, as others pointed out.

> code :
> include("$fpath/forum.php");

That variable is initialized two lines above, so this is BOGUS.

Stefano
...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus