PT-2007-6225 · Simpgb · Simpgb

Published

2007-09-27

·

Updated

2018-10-15

·

CVE-2007-5130

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SimpGB version 1.46.02
Description The issue allows remote attackers to obtain sensitive information. This can be achieved via an invalid lang parameter to the "admin/index.php" API endpoint or a direct request to the "admin/trailer.php" endpoint, which reveals the path in various error messages.
Recommendations For SimpGB version 1.46.02, avoid using the lang parameter in the "admin/index.php" API endpoint until the issue is resolved. Restrict access to the "admin/trailer.php" endpoint to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5130

Affected Products

Simpgb