PT-2005-1404 · Pafiledb · Pafiledb

Devil_Box

·

Publicado

2005-02-10

·

Atualizado

2017-07-11

·

CVE-2005-0326

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PaFileDB version 3.1
Description The issue allows remote attackers to gain sensitive information. This occurs when an invalid or missing action parameter is provided, resulting in an error message that reveals the path when it cannot include a login.php script.
Recommendations For PaFileDB version 3.1, consider restricting access to the pafiledb.php script until a patch is available, or ensure that the action parameter is properly validated to prevent information disclosure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0326

Produtos afetados

Pafiledb