vendor:
IPTBB
by:
sToRm
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: IPTBB
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
IPTBB Local File Inclusion
IPTBB is a free forum system built using PHP and mysql. An attacker can exploit this vulnerability by sending a crafted URL to the application. The URL contains a malicious payload which is appended to the vulnerable parameter. This malicious payload can be used to read sensitive files from the server.
Mitigation:
Input validation should be done on the server side to prevent malicious payloads from being executed.