PT-2004-2871 · Pafiledb · Pafiledb

Darkbicho

·

Publicado

2004-04-27

·

Atualizado

2017-07-11

·

CVE-2004-1974

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions paFileDB version 3.1
Description The issue allows remote attackers to gain sensitive information via a direct request to various API endpoints, including "login.php", "category.php", "search.php", "main.php", "viewall.php", "download.php", "email.php", "file.php", "rate.php", or "stats.php". These endpoints reveal the path in an error message, potentially exposing sensitive information.
Recommendations For paFileDB version 3.1, consider restricting access to the mentioned API endpoints until a patch is available. As a temporary workaround, disable the display of error messages that reveal sensitive path information.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1974

Produtos afetados

Pafiledb