CGIForum allows reading of local files (thesection parameter)
26 Nov. 2000
Summary
CGIForum is a free forum CGI system. A vulnerability in the product allows files referenced by the 'thesection' parameter to be viewed remotely. The impact of this vulnerability is that any file that is readable by the user "nobody" (which is the default user that runs the CGI) can be viewed remotely.
Credit:
The information has been provided by zorgon.