PT-2006-3823 · Unknown · Partial Links
Publicado
2006-06-08
·
Atualizado
2018-10-18
·
CVE-2006-2905
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Partial Links version 1.2.2
Description
The issue allows remote attackers to obtain sensitive information via a direct request to API endpoints such as "page footer.php" and "page header.php", which displays the path in an error message.
Recommendations
For version 1.2.2, consider restricting access to the "page footer.php" and "page header.php" endpoints until a patch is available. As a temporary workaround, modify the error handling in these endpoints to prevent the disclosure of sensitive path information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Partial Links