DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages.
References
Configurations
History
21 Nov 2024, 00:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://securityreason.com/securityalert/2741 - | |
References | () http://www.netvigilance.com/advisory0021 - | |
References | () http://www.osvdb.org/34226 - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/469826/100/0/threaded - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34540 - |
Information
Published : 2007-05-30 20:30
Updated : 2024-11-21 00:26
NVD link : CVE-2007-0692
Mitre link : CVE-2007-0692
CVE.ORG link : CVE-2007-0692
JSON object : View
Products Affected
dgnews
- dgnews
CWE