PT-2005-3251 · Clever · Clever Copy

Lostmon

·

Published

2005-07-19

·

Updated

2008-09-05

·

CVE-2005-2325

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Clever Copy versions 2.0 through 2.0a
Description The issue allows remote attackers to obtain the full path of the web root via a direct request to various API endpoints, including "ticker.php", "menu.php", "banned.php", "endlayout.php", "randomhlinesblock.php", "showlast.php", "showlast5class1.php", "showlast5phorum.php", "showlast5phorumblock.php", "showlastforumbb2.php", or "showlastforumbb2block.php".
Recommendations For Clever Copy versions 2.0 through 2.0a, consider restricting direct access to the mentioned API endpoints as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2325

Affected Products

Clever Copy