easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.
                
            References
                    | Link | Resource | 
|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html | Exploit | 
| http://www.kb.cert.org/vuls/id/597795 | US Government Resource | 
| http://www.securityfocus.com/bid/3649 | Exploit | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/7660 | |
| http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html | Exploit | 
| http://www.kb.cert.org/vuls/id/597795 | US Government Resource | 
| http://www.securityfocus.com/bid/3649 | Exploit | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/7660 | 
Configurations
                    History
                    20 Nov 2024, 23:37
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html - Exploit | |
| References | () http://www.kb.cert.org/vuls/id/597795 - US Government Resource | |
| References | () http://www.securityfocus.com/bid/3649 - Exploit | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/7660 - | 
Information
                Published : 2001-12-01 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2001-1437
Mitre link : CVE-2001-1437
CVE.ORG link : CVE-2001-1437
JSON object : View
Products Affected
                easyscripts
- easynews
 
CWE
                