Advertisement
Home arrow ITsec Advisories arrow FubarForum "page" Local File Inclusion Vulnerability
Saturday, 06 September 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  9885  66.12%
Win 2003  3603  24.10%
Win 2000  935  6.25%
FreeBSD  339  2.27%
SolarisSunOS  102  0.68%
Other  85  0.57%

Total attacks: 14949 of which 4748 single ip and 10201 mass defacements

Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
Visitors' Map
FubarForum "page" Local File Inclusion Vulnerability PDF Print E-mail
User Rating: / 0
PoorBest 
Written by Marcelo Almeida (Vympel)   
Tuesday, 24 June 2008
cOndemned has reported a vulnerability in FubarForum, which can be exploited by malicious people to disclose sensitive information.

Input passed to the "page" parameter in index.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources.

The vulnerability is reported in version 1.5. Prior versions may also be affected... Solution:

Update to version 1.6.

Provided and/or discovered by:
cOndemned

Original Advisory:
FubarForum:
http://chaozz.nl/2008/06/fubarforum-16-released/

cOndemned:
http://milw0rm.com/exploits/5872

Orignal article:
http://secunia.com/advisories/30811/


Comments Index (Total Messages: 0)


Post Reply
Name:Guest
Title:
Comment:



Enter this security word

Powered by a Zone-H(ified) version of AkoComment 3.0!


DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The   author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice.
 
< Prev   Next >
 
Top! Top!