PT-2009-4567 · Skybluecanvas · Skybluecanvas

Published

2009-06-18

·

Updated

2018-10-10

·

CVE-2009-2115

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SkyBlueCanvas version 1.1 r237
Description The issue allows remote authenticated administrators to obtain sensitive information. This is achieved by providing an invalid id parameter, which results in an error message that reveals the installation path.
Recommendations For SkyBlueCanvas version 1.1 r237, consider restricting access to the admin.php file until a patch is available. As a temporary workaround, avoid using the id parameter in the affected admin.php file to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2115

Affected Products

Skybluecanvas