PT-2007-6867 · Pear · Pear Mdb2
Priyadi
·
Publicado
2007-11-13
·
Atualizado
2011-03-08
·
CVE-2007-5934
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PEAR MDB2 versions prior to 2.5.0a1
Description
The issue allows remote attackers to potentially use MDB2 as an indirect proxy or obtain sensitive information by submitting a URL string into a form field in an MDB2 application. This could be achieved by using a
file:// URL or a URL for an intranet web site.Recommendations
For versions prior to 2.5.0a1, update to version 2.5.0a1 or later to resolve the issue. As a temporary workaround, consider restricting the interpretation of URL strings in form fields to prevent potential misuse.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pear Mdb2