index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote (').
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=113087965608496&w=2 | mailing list |
http://irannetjob.com/content/view/152/28/ | url repurposed |