Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Silitix

#48758of 53,630
5Total CVSS
Vulnerabilities · 1
PT-2006-4784
5.0
2006-07-31
Dotclear · Dotclear · CVE-2006-3938
**Name of the Vulnerable Software and Affected Versions** DotClear (affected versions not specified) **Description** The issue allows remote attackers to obtain sensitive information via direct requests for various files, including `edit cat.php`, `index.php`, `edit link.php` in `ecrire/tools/blogroll/`, `syslog/index.php`, `thememng/index.php`, `toolsmng/index.php`, `utf8convert/index.php` in `/ecrire/tools/`, `/ecrire/inc/connexion.php`, `/inc/session.php`, `class.blog.php`, `class.blogcomment.php`, `class.blogpost.php` in `/inc/classes/`, `append.php`, `class.xblog.php`, `class.xblogcomment.php`, `class.xblogpost.php` in `/layout/`, and `form.php`, `list.php`, `post.php`, `template.php` in `/themes/default/`. These files reveal the installation path in error messages. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.