PT-2004-2810 · Nuke · Nukecalendar

Janek Vind

+1

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1912

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NukeCalendar version 1.1.a
Description The issue allows remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message. This is due to the modules.php, block-Calendar.php, block-Calendar1.php, and block-Calendar center.php scripts in NukeCalendar.
Recommendations For NukeCalendar version 1.1.a, consider restricting access to the vulnerable scripts until a patch is available. As a temporary workaround, avoid using invalid arguments in URLs to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1912

Affected Products

Nukecalendar