PT-2006-5768 · Jevon · Jevoncms
Cvir.System
·
Published
2006-09-27
·
Updated
2018-10-17
·
CVE-2006-5027
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JevonCMS versions prior to alpha
Description
The issue allows remote attackers to obtain sensitive information via a direct request for certain php/main/phplib files, including
db msql.inc, db mssql.inc, db mysql.inc, db oci8.inc, db odbc.inc, db oracle.inc, db pgsql.inc, and db sybase.inc. These files reveal the path in various error messages.Recommendations
For JevonCMS versions prior to alpha, consider restricting access to the php/main/phplib directory to minimize the risk of exploitation. As a temporary workaround, avoid using the direct request method for the mentioned files until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jevoncms