PHPNuke Splatt Forum Module Path Disclosure Vulnerability
BID:7080
Info
PHPNuke Splatt Forum Module Path Disclosure Vulnerability
| Bugtraq ID: | 7080 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2003 12:00AM |
| Updated: | Mar 12 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Rynho Zeros Web <[email protected]>. |
| Vulnerable: |
Splatt Forum 3.2 |
| Not Vulnerable: | |
Discussion
PHPNuke Splatt Forum Module Path Disclosure Vulnerability
The Splatt Forum module for PHPNuke has been reported prone to a vulnerability which, when exploited, may disclose sensitive path information to a remote attacker.
An attacker could use the information gathered in this manner to mount further attacks against the host.
This vulnerability was reported to affect Splatt Forums 3.2 other versions may also be affected.
The Splatt Forum module for PHPNuke has been reported prone to a vulnerability which, when exploited, may disclose sensitive path information to a remote attacker.
An attacker could use the information gathered in this manner to mount further attacks against the host.
This vulnerability was reported to affect Splatt Forums 3.2 other versions may also be affected.
Exploit / POC
PHPNuke Splatt Forum Module Path Disclosure Vulnerability
The following proof of concept was provided:
http://www.example.com/modules.php?op=modload&name=Forums&file=attachment&AtchOp=show
The following proof of concept was provided:
http://www.example.com/modules.php?op=modload&name=Forums&file=attachment&AtchOp=show
Solution / Fix
PHPNuke Splatt Forum Module Path Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.