CVE-2002-2158

zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zendocs:zentrack:2.0.1c_beta:*:*:*:*:*:*:*
cpe:2.3:a:zendocs:zentrack:2.0.2c_beta:*:*:*:*:*:*:*
cpe:2.3:a:zendocs:zentrack:2.0.3:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/276121 - () http://online.securityfocus.com/archive/1/276121 -
References () http://www.iss.net/security_center/static/9312.php - () http://www.iss.net/security_center/static/9312.php -
References () http://www.securityfocus.com/bid/4973 - () http://www.securityfocus.com/bid/4973 -

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:43


NVD link : CVE-2002-2158

Mitre link : CVE-2002-2158

CVE.ORG link : CVE-2002-2158


JSON object : View

Products Affected

zendocs

  • zentrack