PT-2005-3884 · Phpmyfaq · Phpmyfaq

Retrogod

·

Published

2005-09-23

·

Updated

2016-10-18

·

CVE-2005-3050

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PhpMyFaq version 1.5.1
Description The issue allows remote attackers to obtain sensitive information. This is achieved via a LANGCODE parameter that does not exist, which reveals the path in an error message.
Recommendations For PhpMyFaq version 1.5.1, avoid using the LANGCODE parameter in affected API endpoints until the issue is resolved. As a temporary workaround, consider restricting access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3050

Affected Products

Phpmyfaq