PT-2004-2412 · Unknown · Just Another Flat File (Jaf) Cms

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-1504

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Just Another Flat file (JAF) CMS version 3.0RC
Description The issue allows remote attackers to gain sensitive information. This is achieved by exploiting the displaycontent function in config.php, which reveals the installation path in an error message when a blank show parameter is used, as demonstrated using index.php.
Recommendations For Just Another Flat file (JAF) CMS version 3.0RC, consider modifying the displaycontent function in config.php to handle blank show parameters securely, preventing the revelation of sensitive installation path information in error messages.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1504

Produtos afetados

Just Another Flat File (Jaf) Cms