PT-2006-6440 · Rhadrix · Rhadrix If-Cms

Benjamin Moss

+1

·

Published

2006-11-06

·

Updated

2024-02-14

·

CVE-2006-5759

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Rhadrix If-CMS versions 1.01 through 2.07
Description: The issue allows remote attackers to obtain the full path of the web server. This is achieved by providing empty arguments, specifically rns[] or pag[], which results in an error message that reveals the path.
Recommendations: For versions 1.01 through 2.07, consider restricting access to the index.php file until a fix is available. As a temporary workaround, avoid using empty rns[] or pag[] arguments in API endpoints to minimize the risk of path disclosure.

Exploit

Fix

Related Identifiers

CVE-2006-5759

Affected Products

Rhadrix If-Cms