Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

R0T3D3Vil

#49572of 53,633
5Total CVSS
Vulnerabilities · 1
PT-2005-4762
5.0
2005-12-05
Geeklog · Geeklog · CVE-2005-4026
**Name of the Vulnerable Software and Affected Versions** Geeklog versions 1.3.x through 1.3.11sr2 Geeklog versions 1.4.x through 1.4.0rc1 **Description** The issue allows remote attackers to obtain sensitive information via invalid `datestart` and `dateend` parameters in the "search.php" file, which leaks the web server path in an error message. **Recommendations** For Geeklog versions 1.3.x through 1.3.11sr2, update to version 1.3.11sr3. For Geeklog versions 1.4.x through 1.4.0rc1, update to version 1.4.0rc1 or later.