PT-2009-3311 · Ravennuke · Ravennuke

Janek Vind

+1

·

Publicado

2009-02-22

·

Atualizado

2018-10-10

·

CVE-2009-0678

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions RavenNuke version 2.30
Description The issue allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, which reveals the installation path in an error message.
Recommendations For RavenNuke version 2.30, consider restricting access to the images/captcha.php file until a patch is available, or apply configuration changes to handle invalid font file requests without revealing sensitive information.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0678

Produtos afetados

Ravennuke