Vulnerable Systems:
* KorWeblog version 1.3 and prior
An input validation error allows a malicious user to exploit this condition in order to map directory names on the server system. KorWeblog has a function to insert image icons when users post replies. This function is implemented in viewimg.php. The function doesn't check user input correctly, so malicious attackers can modify the $path variable and can get file lists of a target directory.