Description: [wHITe_ShEEp] has discovered a vulnerability in fuzzylime (cms), which can be exploited by malicious people to disclose sensitive information.
Input passed to the "p" parameter in code/getgalldata.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources.
Successful exploitation requires that "magic_quotes_gpc" is disabled.
The vulnerability is confirmed in version 3.0. Prior versions may also be affected.
Solution: Update to version 3.01.
Provided and/or discovered by: [wHITe_ShEEp], not sec group
Changelog: 2007-09-13: Added CVE reference.
2007-10-01: Updated "Solution" section.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.