PT-2006-6750 · Unknown · Monkey Boards

Jesper Jurcenoks

·

Published

2006-11-28

·

Updated

2018-10-17

·

CVE-2006-6113

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Monkey Boards version 0.3.5
Description The issue allows remote attackers to obtain sensitive information via direct requests to API endpoints such as "include/admin auth.inc.php" and "include/engine/class.compiler.php". This occurs because these endpoints reveal the full path in an error message. It is noted that this issue only constitutes an exposure if the administrator has changed the default script path.
Recommendations For Monkey Boards version 0.3.5, consider restricting access to the "include/admin auth.inc.php" and "include/engine/class.compiler.php" endpoints to minimize the risk of exploitation. Additionally, administrators should review their script path configurations to ensure they are using the default settings, thereby reducing the exposure risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6113

Affected Products

Monkey Boards