PHPBoost contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered when the /phpboost/user/ script fails to properly sanitized malformed input passed via the 'URL' parameter. This may allow a remote attacker to gain access to php.ini configuration information.
Disclosure Timeline:
Disclosure Date :2013-03-11
Exploit Publish Date :2013-03-11