PT-2008-3261 · Woltlab · Woltlab Burning Board+1

Publicado

2008-04-09

·

Atualizado

2018-10-11

·

CVE-2008-1717

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WoltLab Burning Board version 3.0.5
Description The issue allows remote attackers to obtain the full path via invalid parameters, which leaks the path from an exception handler when a valid class cannot be found. This occurs due to the handling of invalid page and form parameters in WoltLab Community Framework (WCF) 1.0.6 within WoltLab Burning Board 3.0.5.
Recommendations For WoltLab Burning Board version 3.0.5, consider restricting access to the exception handler to minimize the risk of path leakage until a patch is available. As a temporary workaround, avoid using invalid page and form parameters in the affected API endpoints.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1717

Produtos afetados

Woltlab Burning Board
Woltlab Community Framework