PT-2002-2445 · Unknown · Powerboards
Publicado
2002-12-31
·
Atualizado
2017-07-11
·
CVE-2002-1723
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Powerboards version 2.2b
Description
The issue allows remote attackers to view the full path to the backend database. This can be achieved by sending a cookie containing a non-existent
username to the "profiles.php" endpoint, which displays the full path in the error message.Recommendations
For Powerboards version 2.2b, consider restricting access to the "profiles.php" endpoint until a patch is available, or modify the error handling to prevent the disclosure of sensitive path information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Powerboards