Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sympoll File Disclosure Vulnerability

Sympoll 1.2 is prone to an issue which may allow remote attackers to disclose the contents of arbitrary webserver readable files. This vulnerability is only present on hosts which are running the vulnerable version of the software and have the PHP 'register_globals' directive enabled. The source of this vulnerability is reported to be insufficient integrity checking of variables.







 

Privacy Statement
Copyright 2008, SecurityFocus