PT-2007-6867 · Pear · Pear Mdb2
Priyadi
·
Published
2007-11-13
·
Updated
2011-03-08
·
CVE-2007-5934
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PEAR MDB2 versions prior to 2.5.0a1
Description
The issue allows remote attackers to potentially use MDB2 as an indirect proxy or obtain sensitive information by submitting a URL string into a form field in an MDB2 application. This could be achieved by using a
file:// URL or a URL for an intranet web site.Recommendations
For versions prior to 2.5.0a1, update to version 2.5.0a1 or later to resolve the issue. As a temporary workaround, consider restricting the interpretation of URL strings in form fields to prevent potential misuse.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pear Mdb2