PT-2007-6741 · Flatnuke · Flatnuke

Kingoftheworld

·

Publicado

2007-11-01

·

Atualizado

2017-09-29

·

CVE-2007-5774

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flatnuke version 3
Description The issue allows remote attackers to obtain sensitive information. This is achieved by providing an invalid argumentname parameter in a disc op action to the index.php file in the File Manager module, which results in the path being revealed in an error message.
Recommendations For Flatnuke version 3, consider restricting access to the index.php file in the File Manager module until a patch is available. As a temporary workaround, avoid using the argumentname parameter in the affected disc op action to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5774

Produtos afetados

Flatnuke