PT-2008-3261 · Woltlab · Woltlab Burning Board+1
Publicado
2008-04-09
·
Atualizado
2018-10-11
·
CVE-2008-1717
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WoltLab Burning Board version 3.0.5
Description
The issue allows remote attackers to obtain the full path via invalid parameters, which leaks the path from an exception handler when a valid class cannot be found. This occurs due to the handling of invalid
page and form parameters in WoltLab Community Framework (WCF) 1.0.6 within WoltLab Burning Board 3.0.5.Recommendations
For WoltLab Burning Board version 3.0.5, consider restricting access to the exception handler to minimize the risk of path leakage until a patch is available. As a temporary workaround, avoid using invalid
page and form parameters in the affected API endpoints.Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Woltlab Burning Board
Woltlab Community Framework