Invision.Board.PHPINFO.PHP.Information.Disclosure

description-logoDescription

The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.

affected-products-logoAffected Products

Invision Power Services Invision Board 1.0.1
Invision Power Services Invision Board 1.0

Impact logoImpact

Information disclosure.

recomended-action-logoRecommended Actions

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: Remove the phpinfo.php file from the web server.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)