PT-2005-4753 · Unknown · Widget Property
Published
2005-12-05
·
Updated
2008-09-20
·
CVE-2005-4017
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Widget Property version 1.1.19
Description
The issue allows remote attackers to obtain the full server path via an invalid
lang value. This is achieved by exploiting the property.php file, which leaks the path in the resulting error message.Recommendations
For version 1.1.19, consider validating and sanitizing the
lang value to prevent path disclosure. As a temporary workaround, restrict access to the property.php file until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Widget Property