Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or RavenNuke(tm)?Need help customizing or designing scripts?Please contact us via the Contact Us option for further details and pricing.
SOFTWARE: Multi SEO phpBB 1.x - http://secunia.com/advisories/product/20660/
DESCRIPTION: NoGe has discovered a vulnerability in Multi SEO phpBB, which can be exploited by malicious people to compromise a vulnerable system. This vulnerability is confirmed in version 1.1.0. Other versions may also be affected.
Input passed to the "pfad" parameter in include/global.php is not
properly verified before being used to include files. This can be
exploited to include arbitrary files from local and external
resources via URL-encoded NULL bytes.
SOLUTION: Edit the source code to ensure that input is properly verified.
PROVIDED AND/OR DISCOVERED BY: NoGe
ORIGINAL ADVISORY: http://milw0rm.com/exploits/7335
Posted on Thursday, December 04, 2008 @ 16:40:13 EST by Raven