PT-2005-4753 · Unknown · Widget Property
Publicado
2005-12-05
·
Atualizado
2008-09-20
·
CVE-2005-4017
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Widget Property version 1.1.19
Description
The issue allows remote attackers to obtain the full server path via an invalid
lang value. This is achieved by exploiting the property.php file, which leaks the path in the resulting error message.Recommendations
For version 1.1.19, consider validating and sanitizing the
lang value to prevent path disclosure. As a temporary workaround, restrict access to the property.php file until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Widget Property