PT-2004-2479 · Aj Fork · Aj-Fork

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1571

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions AJ-Fork version 167
Description The issue allows remote attackers to gain sensitive information via a direct request to various PHP files, including "auto-acronyms.php", "auto-archive.php", "ount-article-views.php", "kses.php", "custom-quick-tags.php", "disable-all-comments.php", "easy-date-format.php", "enable-disable-comments.php", "filter-by-author.php", "format-switcher.php", "long-to-short.php", "prospective-posting.php", or "sort-by-xfield.php". These files display the full path in an error message.
Recommendations For AJ-Fork version 167, consider restricting access to the mentioned PHP files to minimize the risk of exploitation. As a temporary workaround, disable the display of error messages that include the full path for these files until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1571

Affected Products

Aj-Fork