PT-2007-6867 · Pear · Pear Mdb2

Priyadi

·

Publicado

2007-11-13

·

Atualizado

2011-03-08

·

CVE-2007-5934

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PEAR MDB2 versions prior to 2.5.0a1
Description The issue allows remote attackers to potentially use MDB2 as an indirect proxy or obtain sensitive information by submitting a URL string into a form field in an MDB2 application. This could be achieved by using a file:// URL or a URL for an intranet web site.
Recommendations For versions prior to 2.5.0a1, update to version 2.5.0a1 or later to resolve the issue. As a temporary workaround, consider restricting the interpretation of URL strings in form fields to prevent potential misuse.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5934

Produtos afetados

Pear Mdb2