PT-2005-4753 · Unknown · Widget Property

Publicado

2005-12-05

·

Atualizado

2008-09-20

·

CVE-2005-4017

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Widget Property version 1.1.19
Description The issue allows remote attackers to obtain the full server path via an invalid lang value. This is achieved by exploiting the property.php file, which leaks the path in the resulting error message.
Recommendations For version 1.1.19, consider validating and sanitizing the lang value to prevent path disclosure. As a temporary workaround, restrict access to the property.php file until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4017

Produtos afetados

Widget Property