CVE-2008-5418 Information

Description

Directory traversal vulnerability in login.php in the PunPortal module before 2.0 for PunBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter.

Reference

http://securityreason.com/securityalert/4707 http://www.securityfocus.com/bid/32380 https://exchange.xforce.ibmcloud.com/vulnerabilities/46774 https://www.exploit-db.com/exploits/7168

Share on: