Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/16578 | vdb entry |
http://www.securityfocus.com/archive/1/424708 | mailing list exploit vendor advisory |
http://retrogod.altervista.org/runcms_13a_xpl.html | exploit |