PT-2005-3759 · Web//News · Web//News
Onkel_Fisch
+1
·
Published
2005-09-14
·
Updated
2016-10-18
·
CVE-2005-2897
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WEB//NEWS version 1.4
Description
The issue allows remote attackers to obtain sensitive information via a direct request to files in the actions directory. This is possible because the error messages from these files reveal the path. For example, this can be demonstrated by accessing the "cat.add.php" file.
Recommendations
For WEB//NEWS version 1.4, consider restricting access to the actions directory to prevent remote attackers from obtaining sensitive information. As a temporary workaround, modify the error handling to prevent the disclosure of sensitive path information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Web//News