Aborior Encore Web Forum Remote Arbitrary Command Execution Vulnerability

Encore Web Forum is reported prone to an issue that may allow a remote user to execute arbitrary commands on a system implementing the forum software. This issue is due to the application's failure to properly validate user-supplied URI input.

A remote attacker may exploit this condition to execute arbitrary commands in the context of the webserver that is hosting the vulnerable application.


 

Privacy Statement
Copyright 2010, SecurityFocus