Hello frnds..Today i wiil tell you how to secure your IPB 3.4.2 < versions from Full Path Disclosure..
# Vulnerability: Full Path Disclosure# Solution: Upgrade to version 3.4.3
#But no need upgrade in this tut
It works on v.3.4.2 and less.Will be patched in v.3.4.3. To reproduce this issue do this:http://www.example-site.com/index.php?app=core&module=search&do=search&search_app_filters[]=date&search_term=trolololoGuilty is variable 'search_app_filters' which wait to receive doubled-array(forums][sortKey]). If it doesn't get it correctly then errors with Full Path show up. Normal request would looks like this:http://www.example-site.com/index.php?app=core&module=search&do=search&search_app_filters[forums][sortKey]=date&search_term=trolololo
#How To Secure : Open your cpanel > Open file manager > Open Forum root folder
#Make a new file as "php.ini"
#Open php.ini in text editer
# paste this command
display_errors = Off
#Save and close.Bingo your Vulnerability Patched Thnkx for reading my tut...in next tut i will tell you "How to secure your forum from server rooting"..