QSF Portal "lang" File Inclusion Vulnerability

by Carol~ Moderator - 2/22/10 3:33 AM

In Reply to: VULNERABILITIES \ FIXES - February 22, 2010 by Carol~ Moderator

Release Date : 2010-02-22

Criticality level : Moderately critical
Impact :Exposure of system information
Exposure of sensitive information
Where : From remote
Solution Status : Vendor Patch

Software : QSF Portal 1.x

Description
A vulnerability has been reported in QSF Portal, which can be exploited by malicious people to disclose sensitive information.

The vulnerability is caused due to the usage of vulnerable Quicksilver Forums code.

Solution
Update to version 1.4.5.

Original Advisory
http://www.qsfportal.com/index.php?a=newspost&t=191

http://secunia.com/advisories/38670/