Ultimate PHP Board Information Disclosure Vulnerability
BID:5858
Info
Ultimate PHP Board Information Disclosure Vulnerability
| Bugtraq ID: | 5858 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Oct 02 2002 12:00AM |
| Credit: | Discovery credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Ultimate PHP Board Ultimate PHP Board 1.0 b |
| Not Vulnerable: | |
Discussion
Ultimate PHP Board Information Disclosure Vulnerability
A vulnerability has been discovered in Ultimate PHP Board.
It has been reported that by including the path to sensitive files in a web request, it is possible for an unauthorized user to access PHP board data files. This is due to insufficient input validation.
This vulnerability was reported for version 1.0b. It is not known whether other versions are affected.
A vulnerability has been discovered in Ultimate PHP Board.
It has been reported that by including the path to sensitive files in a web request, it is possible for an unauthorized user to access PHP board data files. This is due to insufficient input validation.
This vulnerability was reported for version 1.0b. It is not known whether other versions are affected.
Exploit / POC
Ultimate PHP Board Information Disclosure Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
Ultimate PHP Board Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ultimate PHP Board Information Disclosure Vulnerability
References:
References:
- Ultimate PHP Board Product Page. (www.webrc.ca)