PT-2004-2412 · Unknown · Just Another Flat File (Jaf) Cms

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1504

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Just Another Flat file (JAF) CMS version 3.0RC
Description The issue allows remote attackers to gain sensitive information. This is achieved by exploiting the displaycontent function in config.php, which reveals the installation path in an error message when a blank show parameter is used, as demonstrated using index.php.
Recommendations For Just Another Flat file (JAF) CMS version 3.0RC, consider modifying the displaycontent function in config.php to handle blank show parameters securely, preventing the revelation of sensitive installation path information in error messages.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1504

Affected Products

Just Another Flat File (Jaf) Cms