PT-2008-3261 · Woltlab · Woltlab Burning Board+1
Published
2008-04-09
·
Updated
2018-10-11
·
CVE-2008-1717
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WoltLab Burning Board version 3.0.5
Description
The issue allows remote attackers to obtain the full path via invalid parameters, which leaks the path from an exception handler when a valid class cannot be found. This occurs due to the handling of invalid
page and form parameters in WoltLab Community Framework (WCF) 1.0.6 within WoltLab Burning Board 3.0.5.Recommendations
For WoltLab Burning Board version 3.0.5, consider restricting access to the exception handler to minimize the risk of path leakage until a patch is available. As a temporary workaround, avoid using invalid
page and form parameters in the affected API endpoints.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woltlab Burning Board
Woltlab Community Framework