PT-2002-1497 · Black Tie · Black Tie Project

Publicado

2002-06-11

·

Atualizado

2008-09-05

·

CVE-2002-0446

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Black Tie Project (BTP) versions 0.4b through 0.5b
Description The issue allows remote attackers to determine the absolute path of the web server via an invalid cid parameter in the categorie.php3 file, which leaks the pathname in an error message.
Recommendations For Black Tie Project (BTP) versions 0.4b through 0.5b, consider validating and sanitizing the cid parameter to prevent the disclosure of the web server's absolute path. As a temporary workaround, restrict access to the categorie.php3 file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0446

Produtos afetados

Black Tie Project