Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RETIRED: phpMyConferences PageTraiteDownload.PHP Local File Include Vulnerability

phpMyConferences is prone to a local file-include vulnerability because it fails to adequately sanitize user-supplied input for requests to restricted files that reside outside of the web document root directory.

A remote attacker can exploit this issue to retrieve potentially sensitive information that may aid in further attacks.

This issue affects phpMyConferences 8.0.2; other versions may also be affected.

NOTE: This BID is being retired. The affected script does not work, so this issue cannot be exploited in the manner specified.







 

Privacy Statement
Copyright 2009, SecurityFocus