PT-2007-3246 · Sonicbb · Sonicbb

Jesper Jurcenoks

·

Publicado

2007-05-14

·

Atualizado

2018-10-16

·

CVE-2007-1901

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SonicBB version 1.0
Description: The issue allows remote attackers to obtain sensitive information. This is achieved via the by[] parameter to "search.php", the p[] parameter to "viewforum.php", and the id parameter to either "viewforum.php" or "members.php". The installation path is revealed in the resulting error message.
Recommendations: For SonicBB version 1.0, as a temporary workaround, consider restricting access to the "search.php", "viewforum.php", and "members.php" scripts until a patch is available. Avoid using the by[] and p[] parameters in the affected API endpoints, and restrict the use of the id parameter in "viewforum.php" and "members.php" to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1901

Produtos afetados

Sonicbb