PT-2004-2479 · Aj Fork · Aj-Fork
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-1571
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AJ-Fork version 167
Description
The issue allows remote attackers to gain sensitive information via a direct request to various PHP files, including "auto-acronyms.php", "auto-archive.php", "ount-article-views.php", "kses.php", "custom-quick-tags.php", "disable-all-comments.php", "easy-date-format.php", "enable-disable-comments.php", "filter-by-author.php", "format-switcher.php", "long-to-short.php", "prospective-posting.php", or "sort-by-xfield.php". These files display the full path in an error message.
Recommendations
For AJ-Fork version 167, consider restricting access to the mentioned PHP files to minimize the risk of exploitation. As a temporary workaround, disable the display of error messages that include the full path for these files until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aj-Fork