vendor:
Dynamic Flash Forum
by:
Salvatore 'drosophila' Fresta
7.5
CVSS
HIGH
Information Disclosure, Authentication Bypass, Multiple SQL Injection
200, 287, 89
CWE
Product Name: Dynamic Flash Forum
Affected Version From: 1.0 Beta
Affected Version To: 1.0 Beta
Patch Exists: YES
Related CWE: N/A
CPE: a:dynamic_flash_forum:dynamic_flash_forum:1.0_beta
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Dynamic Flash Forum
This file contains reserved informations such as the username and the password for connecting to the database. Using .inc extension only, the content is visible. This bug allows a guest to bypass the authentication system and to login with administrator privileges. This bug allows a guest to execute arbitrary queries.
Mitigation:
Ensure that the magic_quotes_gpc is set to 'on' and that the .inc extension is not used for files containing sensitive information.