CVE-2005-2571 Information

Description

FunkBoard 0.66CF and possibly earlier versions does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts which allows attackers to obtain the database username and password or inject arbitrary PHP code into info.php.

Reference

http://marc.info/?l=bugtraq&m=112360702307424&w=2 http://marc.info/?l=bugtraq&m=112413891603018&w=2 http://www.funkboard.co.uk/forum/thread.php?id=265

Share on: