vendor:
FUDforum
by:
Tim Coen of Curesec GmbH
4
CVSS
MEDIUM
LFI
22
CWE
Product Name: FUDforum
Affected Version From: 3.0.6
Affected Version To: 3.0.6
Patch Exists: NO
Related CWE: n/a
CPE: a:fudforum:fudforum:3.0.6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
FUDforum 3.0.6 LFI
FUDforum is forum software written in PHP. In version 3.0.6, it is vulnerable to local file inclusion. This allows an attacker to read arbitrary files that the web user has access to. Admin credentials are required.
Mitigation:
This issue was not fixed by the vendor.