Vulnerabilities > CVE-2002-1460 - Unspecified vulnerability in Leszek Krupinski L-Forum 2.4.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
leszek-krupinski

Summary

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

Vulnerable Configurations

Part Description Count
Application
Leszek_Krupinski
1