PT-2006-2139 · Aztek · Aztek Forum

Lorenzo

·

Published

2006-03-09

·

Updated

2018-10-18

·

CVE-2006-1112

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Aztek Forum version 4.0
Description The issue allows remote attackers to obtain sensitive information via a long login value in a register form. This is achieved by triggering a MySQL error message that displays the installation path.
Recommendations For Aztek Forum version 4.0, consider restricting access to the register form to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using long login values in the register form to prevent the display of sensitive information in MySQL error messages.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1112

Affected Products

Aztek Forum