PT-2005-3251 · Clever · Clever Copy

Lostmon

·

Publicado

2005-07-19

·

Atualizado

2008-09-05

·

CVE-2005-2325

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Clever Copy versions 2.0 through 2.0a
Description The issue allows remote attackers to obtain the full path of the web root via a direct request to various API endpoints, including "ticker.php", "menu.php", "banned.php", "endlayout.php", "randomhlinesblock.php", "showlast.php", "showlast5class1.php", "showlast5phorum.php", "showlast5phorumblock.php", "showlastforumbb2.php", or "showlastforumbb2block.php".
Recommendations For Clever Copy versions 2.0 through 2.0a, consider restricting direct access to the mentioned API endpoints as a temporary workaround until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2325

Produtos afetados

Clever Copy