PT-2009-4860 · Siteframe · Siteframe

Published

2009-07-13

·

Updated

2017-08-17

·

CVE-2009-2443

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Siteframe versions 3.2.3 and other 3.2.x versions
Description The issue allows remote attackers to obtain configuration information by making a direct request to 'phpinfo.php', which calls the phpinfo function. This provides sensitive details about the system configuration.
Recommendations For Siteframe versions 3.2.3 and other 3.2.x versions, consider restricting access to the 'phpinfo.php' file to prevent unauthorized disclosure of configuration information. As a temporary workaround, remove or rename the 'phpinfo.php' file until a more permanent solution is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2443

Affected Products

Siteframe