auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
References
Link | Resource |
---|---|
http://secunia.com/advisories/15029 | |
http://securitytracker.com/id?1013779 | Exploit |
http://www.osvdb.org/15706 | |
http://www.phpbb-auction.com/sutra5600.html | Exploit Patch |
http://www.snkenjoi.com/secadv/secadv9.txt | Exploit |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-05-02 04:00
Updated : 2024-02-04 16:52
NVD link : CVE-2005-1235
Mitre link : CVE-2005-1235
CVE.ORG link : CVE-2005-1235
JSON object : View
Products Affected
phpbb_group
- phpbb-auction
CWE