PT-2006-3811 · Gantty · Gantty

Luny

·

Published

2006-06-07

·

Updated

2018-10-18

·

CVE-2006-2893

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GANTTy version 1.0.3
Description The issue allows remote attackers to obtain the full path of the web server. This is achieved by providing an invalid lang parameter in an authenticate action to the "index.php" endpoint.
Recommendations For GANTTy version 1.0.3, consider validating the lang parameter to prevent disclosure of the web server's path. As a temporary workaround, restrict access to the "index.php" endpoint to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2893

Affected Products

Gantty