CVE-2005-1586 Information

Description

Quick.Forum 2.1.6 stores potentially sensitive information such as usernames banned IP addresses censored words and backups under the web document root which allows remote attackers to obtain that information via a direct request to (1) db/users.txt (2) db/banList.txt (3) db/censureWords.txt or (4) backup files.

Reference

http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html http://secunia.com/advisories/15200 http://www.osvdb.org/16328 http://www.osvdb.org/16329

Share on: