PT-2005-1404 · Pafiledb · Pafiledb

Devil_Box

·

Published

2005-02-10

·

Updated

2017-07-11

·

CVE-2005-0326

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PaFileDB version 3.1
Description The issue allows remote attackers to gain sensitive information. This occurs when an invalid or missing action parameter is provided, resulting in an error message that reveals the path when it cannot include a login.php script.
Recommendations For PaFileDB version 3.1, consider restricting access to the pafiledb.php script until a patch is available, or ensure that the action parameter is properly validated to prevent information disclosure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0326

Affected Products

Pafiledb