PT-2009-3311 · Ravennuke · Ravennuke

Janek Vind

+1

·

Published

2009-02-22

·

Updated

2018-10-10

·

CVE-2009-0678

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions RavenNuke version 2.30
Description The issue allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, which reveals the installation path in an error message.
Recommendations For RavenNuke version 2.30, consider restricting access to the images/captcha.php file until a patch is available, or apply configuration changes to handle invalid font file requests without revealing sensitive information.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0678

Affected Products

Ravennuke