|
Leszek Krupinski L-Forum File Disclosure Vulnerability
Reportedly, L-Forum may disclose contents of arbitrary files to attackers. The file upload mechanism in L-Forum doesn't properly check the existence of four global variables (attachment, attachment_name, attachment_size and attachment_type) that are set for every uploaded file. Thus an attacker may be able to obtain access to arbitrary system files. |
|
|
Privacy Statement |