FSboard Directory Traversal Vulnerability
BID:14111
Info
FSboard Directory Traversal Vulnerability
| Bugtraq ID: | 14111 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2005 12:00AM |
| Updated: | Jun 30 2005 12:00AM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
FSboard FSboard 2.0 |
| Not Vulnerable: | |
Discussion
FSboard Directory Traversal Vulnerability
FSboard is prone to a directory traversal vulnerability.
This could allow a remote attacker to read files outside the Web root. This could only be used to access files to which the Web server has permission.
All versions of FSboard are vulnerable to this issue at the moment.
FSboard is prone to a directory traversal vulnerability.
This could allow a remote attacker to read files outside the Web root. This could only be used to access files to which the Web server has permission.
All versions of FSboard are vulnerable to this issue at the moment.
Exploit / POC
FSboard Directory Traversal Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/forum/default.asp?db=general&mode=download&idx=507&fileNum=1&filename=../conf.asp&nav=viewcontents&srhctgr=&srhstr=&page=1
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/forum/default.asp?db=general&mode=download&idx=507&fileNum=1&filename=../conf.asp&nav=viewcontents&srhctgr=&srhstr=&page=1
Solution / Fix
FSboard Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.