Eupla Foros Config.INC Information Disclosure Vulnerability
BID:18817
CVE-2006-3371 |Info
Eupla Foros Config.INC Information Disclosure Vulnerability
| Bugtraq ID: | 18817 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2006 12:00AM |
| Updated: | Jul 05 2006 05:54PM |
| Credit: | DarkFig is credited with the discovery of this vulnerability. |
| Vulnerable: |
eupla.org Foros 0 |
| Not Vulnerable: | |
Discussion
Eupla Foros Config.INC Information Disclosure Vulnerability
Foros is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.
An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.
Note that this vulnerability occurs only when the '.inc' file extension is not declared as a PHP suffix.
Foros is prone to an information-disclosure vulnerability. This issue occurs because access controls on configuration files are not properly set.
An attacker can exploit this issue to retrieve potentially sensitive information. This may aid in further attacks.
Note that this vulnerability occurs only when the '.inc' file extension is not declared as a PHP suffix.
Exploit / POC
Eupla Foros Config.INC Information Disclosure Vulnerability
This issue can be exploited via a web client.
This issue can be exploited via a web client.
Solution / Fix
Eupla Foros Config.INC Information Disclosure Vulnerability
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any official vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].