L-Forum 2.40 and earlier does not properly verify whether a...
Vulnerability Description
L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-1460
Credits & Attribution
No credits recorded in the NVD database.
References
- http://sourceforge.net/tracker/index.php?func=detail&aid=579278&group_id=53716&atid=471343
- http://sourceforge.net/tracker/download.php?group_id=53716&atid=471343&file_id=26687&aid=579278
- http://www.iss.net/security_center/static/9839.php
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0115.html
- http://www.securityfocus.com/bid/5463
More from leszek krupinski
View All →Affected Vendor
leszek krupinski
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.