index.php in GANTTy 1.0.3 allows remote attackers to obtain the full path of the web server via an invalid lang parameter in an authenticate action.
References
Configurations
History
21 Nov 2024, 00:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20498 - | |
References | () http://securityreason.com/securityalert/1060 - | |
References | () http://www.securityfocus.com/archive/1/436125/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/18296 - Exploit | |
References | () http://www.vupen.com/english/advisories/2006/2188 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26964 - |
Information
Published : 2006-06-07 10:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-2893
Mitre link : CVE-2006-2893
CVE.ORG link : CVE-2006-2893
JSON object : View
Products Affected
gantty
- gantty
CWE