Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

myPHPNuke Information Disclosure Vulnerability

An information disclosure vulnerability has been reported for myPHPNuke. The vulnerability exists due to insufficient checks performed in the system_footer.php script file. The system_footer.php script calls the phpinfo() function without checking who the user is.

An attacker can exploit this vulnerability by making a request for the system_footer.php script. The system will respond by disclosing information to a remote attacker.







 

Privacy Statement
Copyright 2008, SecurityFocus