Mambo Flyspray Startdown.PHP Information Disclosure Vulnerability

Mambo Flyspray is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied parameters.

An attacker can exploit this issue to retrieve arbitrary files with the privileges of the vulnerable application. Information harvested during successful exploits will aid in further attacks.

Mambo Flyspray 1.0.1 and prior versions are vulnerable to this issue.


 

Privacy Statement
Copyright 2010, SecurityFocus