PT-2008-3261 · Woltlab · Woltlab Burning Board+1

Published

2008-04-09

·

Updated

2018-10-11

·

CVE-2008-1717

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WoltLab Burning Board version 3.0.5
Description The issue allows remote attackers to obtain the full path via invalid parameters, which leaks the path from an exception handler when a valid class cannot be found. This occurs due to the handling of invalid page and form parameters in WoltLab Community Framework (WCF) 1.0.6 within WoltLab Burning Board 3.0.5.
Recommendations For WoltLab Burning Board version 3.0.5, consider restricting access to the exception handler to minimize the risk of path leakage until a patch is available. As a temporary workaround, avoid using invalid page and form parameters in the affected API endpoints.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1717

Affected Products

Woltlab Burning Board
Woltlab Community Framework