PT-2006-1952 · Invision · Invision Power Board
Publicado
2006-02-28
·
Atualizado
2018-10-18
·
CVE-2006-0909
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Invision Power Board (IPB) versions 2.1.4 and earlier
Description
The issue allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages. This affects various scripts in different directories, including ips kernel, sources/sql, sources/acp loaders, sources/action admin, sources/action public, sources/classes, sources/components acp, sources/handlers, sources/lib, and sources/loginauth.
Recommendations
For Invision Power Board (IPB) versions 2.1.4 and earlier, consider updating to a version later than 2.1.4 to resolve the issue. If an update is not available, as a temporary workaround, restrict access to the vulnerable PHP scripts to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Invision Power Board