PT-2005-1927 · Nuke · Nukebookmarks

Astharot

+1

·

Published

2005-03-26

·

Updated

2016-10-18

·

CVE-2005-0900

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NukeBookmarks version 0.6
Description The issue allows remote attackers to obtain sensitive information via an invalid file or category parameter in the marks.php file, which reveals the path in an error message.
Recommendations For NukeBookmarks version 0.6, consider validating and sanitizing the file and category parameters to prevent the disclosure of sensitive information. As a temporary workaround, restrict access to the marks.php file until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0900

Affected Products

Nukebookmarks