index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has terminology problems and lack of relevant details. The description is based partially on feedback comments.
References
Configurations
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://pridels0.blogspot.com/2005/12/ezdatabase-vuln.html - | |
References | () http://secunia.com/advisories/18043 - Vendor Advisory | |
References | () http://www.osvdb.org/21798 - | |
References | () http://www.securityfocus.com/bid/15908 - Exploit |
Information
Published : 2005-12-17 00:03
Updated : 2025-04-03 01:03
NVD link : CVE-2005-4304
Mitre link : CVE-2005-4304
CVE.ORG link : CVE-2005-4304
JSON object : View
Products Affected
indexcor
- ezdatabase
CWE