>> DeluxeBB "templatefolder" Parameter Handling Local File Inclusion Vulnerability
Title : DeluxeBB "templatefolder" Parameter Handling Local File Inclusion Vulnerability VUPEN ID : VUPEN/ADV-2006-3857 CVE ID : CVE-2006-5154
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-02
Technical Description
A vulnerability has been identified in DeluxeBB, which could be exploited by remote attackers to gain knowledge of sensitive information. This flaw is due to an input validation error in the "templates/deluxe/cp/sig.php" script that does not validate the "templatefolder" parameter, which could be exploited by remote attackers to include or disclose the contents of arbitrary files with the privileges of the web server.