Forum 5 PM.PHP Local File Include Vulnerability

Forum 5 is prone to a local file-include vulnerability.

The application fails to sanitize user input when executing the script. In particular the script fails to check for the presence of a directory-traversal sequence ('../').

A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.

There is no specific affected version information available.


 

Privacy Statement
Copyright 2010, SecurityFocus