PT-2007-2066 · Unknown · Advanced Guestbook

Published

2007-05-09

·

Updated

2018-10-16

·

CVE-2007-0608

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advanced Guestbook version 2.4.2
Description The issue allows remote attackers to obtain sensitive information. This can be achieved through various methods, including:
  • An invalid GB TBL parameter to "lang/codes-english.php" or "image.php", which reveals the database name;
  • An invalid GB DB parameter to "index.php", coupled with a "../index" lang cookie, which reveals the installation path;
  • A direct request to "index.php" with no parameters or cookies, which also reveals the installation path.
Recommendations For Advanced Guestbook version 2.4.2, consider restricting access to the sensitive parameters GB TBL and GB DB until a patch is available. As a temporary workaround, avoid using invalid parameters in requests to "lang/codes-english.php", "image.php", and "index.php" to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0608

Affected Products

Advanced Guestbook