PT-2006-6896 · Postnuke · Postnuke

Published

2006-12-04

·

Updated

2018-10-17

·

CVE-2006-6267

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions PostNuke versions 0.7.5.0 and certain minor versions
Description The issue allows remote attackers to obtain sensitive information by providing a non-numeric value for the stop parameter, which reveals the path in an error message.
Recommendations For PostNuke versions 0.7.5.0 and certain minor versions, consider validating the stop parameter to ensure it only accepts numeric values to prevent information disclosure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6267

Affected Products

Postnuke