PT-2002-1497 · Black Tie · Black Tie Project

Published

2002-06-11

·

Updated

2008-09-05

·

CVE-2002-0446

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Black Tie Project (BTP) versions 0.4b through 0.5b
Description The issue allows remote attackers to determine the absolute path of the web server via an invalid cid parameter in the categorie.php3 file, which leaks the pathname in an error message.
Recommendations For Black Tie Project (BTP) versions 0.4b through 0.5b, consider validating and sanitizing the cid parameter to prevent the disclosure of the web server's absolute path. As a temporary workaround, restrict access to the categorie.php3 file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0446

Affected Products

Black Tie Project