PT-2006-3823 · Unknown · Partial Links
Published
2006-06-08
·
Updated
2018-10-18
·
CVE-2006-2905
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Partial Links version 1.2.2
Description
The issue allows remote attackers to obtain sensitive information via a direct request to API endpoints such as "page footer.php" and "page header.php", which displays the path in an error message.
Recommendations
For version 1.2.2, consider restricting access to the "page footer.php" and "page header.php" endpoints until a patch is available. As a temporary workaround, modify the error handling in these endpoints to prevent the disclosure of sensitive path information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Partial Links