PT-2005-1404 · Pafiledb · Pafiledb
Devil_Box
·
Published
2005-02-10
·
Updated
2017-07-11
·
CVE-2005-0326
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PaFileDB version 3.1
Description
The issue allows remote attackers to gain sensitive information. This occurs when an invalid or missing
action parameter is provided, resulting in an error message that reveals the path when it cannot include a login.php script.Recommendations
For PaFileDB version 3.1, consider restricting access to the pafiledb.php script until a patch is available, or ensure that the
action parameter is properly validated to prevent information disclosure.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pafiledb