Leszek Krupinski L-Forum File Disclosure Vulnerability

Reportedly, L-Forum may disclose contents of arbitrary files to attackers. The file upload mechanism in L-Forum doesn't properly check the existence of four global variables (attachment, attachment_name, attachment_size and attachment_type) that are set for every uploaded file.

Thus an attacker may be able to obtain access to arbitrary system files.


