|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
TinyPHPForum contains a flaw that may allow a malicious user to view or create files in arbitrary locations on the server's file system. The issue is triggered when the 'uname' variable contains file system traversal characters, such as dot-dot-slash submitted to the 'profile.php' script. It is possible that the flaw may allow the web server to view or create files in arbitrary locations in the file system. resulting in a loss of confidentiality and integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
TinyPHPForum
 |
3.6 |
|
|
|
|
Credit |
- Aliaksandr Hartsuyeu - alex
evuln.com - eVuln
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|