5
CVSSv2

CVE-2002-1423

Published: 11/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

tmp_view.php in FUDforum prior to 2.2.0 allows remote malicious users to read arbitrary files via an absolute pathname in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ilia alshanetsky fudforum 1.9.8

ilia alshanetsky fudforum 2.0.2

ilia alshanetsky fudforum 1.2.8

Exploits

source: wwwsecurityfocuscom/bid/5501/info Reportedly, FUDForum may disclose contents of arbitrary files to attackers The vulnerability is the result of FUDForum failing to check the path of the file that is being requested By simply making malicious requests via URI parameters, an attacker is able to obtain access to potentially sensiti ...