Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SIR GNUBoard File Upload Extension Restriction Bypass Vulnerability

An exploit is not required. This issue can be leveraged by changing the case of the file extension of a script file. For example files with .php, .cgi, .htm, and .pl extensions would be blocked, but files with .pHp, .cgI, .Htm, and .PL extensions would not.







 

Privacy Statement
Copyright 2009, SecurityFocus