Family: CGI abuses --> Category: infos
phpMyFAQ action parameter arbitrary file disclosure vulnerability Vulnerability Scan
Vulnerability Scan Summary
Check the version of phpMyFAQ
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP script that permits information
disclosure of local files.
The version of phpMyFAQ on the remote host contains a flaw that may lead
to an unauthorized information disclosure. The problem is that user
input passed to the 'action' parameter is not properly verified before
being used to include files, which could allow an remote attacker to
view any accessible file on the system, resulting in a loss of
See also :
Upgrade to phpMyFAQ 1.3.13 or newer.
Low / CVSS Base Score : 2
Click HERE for more information and discussions on this network vulnerability scan.