SonicBB 1.0 allows remote attackers to obtain sensitive information via the (1) by[] parameter to search.php, (2) p[] parameter to viewforum.php, and the (3) id parameter to (a) viewforum.php or (b) members.php, which reveal the installation path in the resulting error message.
References
Configurations
History
21 Nov 2024, 00:29
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=full-disclosure&m=117914586003786&w=2 - | |
References | () http://osvdb.org/34701 - | |
References | () http://osvdb.org/34702 - | |
References | () http://osvdb.org/34703 - | |
References | () http://secunia.com/advisories/25279 - | |
References | () http://www.netvigilance.com/advisory0018 - Vendor Advisory | |
References | () http://www.osvdb.org/33906 - | |
References | () http://www.securityfocus.com/archive/1/468535/100/0/threaded - | |
References | () http://www.vupen.com/english/advisories/2007/1816 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34259 - |
Information
Published : 2007-05-14 21:19
Updated : 2024-11-21 00:29
NVD link : CVE-2007-1901
Mitre link : CVE-2007-1901
CVE.ORG link : CVE-2007-1901
JSON object : View
Products Affected
sonicbb
- sonicbb
CWE