Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659. Succesful exploitation requires that register_globals On & allow_url_fopen On
Publication date: Mon, 17 Apr 2006 15:02:00 +0000