The search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via certain requests, possibly related to the $info{'forum'} variable.Referenceshttp://www.web-app.net/cgi-bin/index.cgi?action=downloadinfo&cat=security&id=1http://www.web-app.net/cgi-bin/index.cgi?action=redirectd&cat=security&id=1