PT-2005-4753 · Unknown · Widget Property

Published

2005-12-05

·

Updated

2008-09-20

·

CVE-2005-4017

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Widget Property version 1.1.19
Description The issue allows remote attackers to obtain the full server path via an invalid lang value. This is achieved by exploiting the property.php file, which leaks the path in the resulting error message.
Recommendations For version 1.1.19, consider validating and sanitizing the lang value to prevent path disclosure. As a temporary workaround, restrict access to the property.php file until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4017

Affected Products

Widget Property