auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
References
Link | Resource |
---|---|
http://www.snkenjoi.com/secadv/secadv9.txt | Exploit |
http://www.phpbb-auction.com/sutra5600.html | Exploit Patch |
http://www.osvdb.org/15706 | |
http://securitytracker.com/id?1013779 | Exploit |
http://secunia.com/advisories/15029 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-05-01 21:00
Updated : 2008-09-05 13:48
NVD link : CVE-2005-1235
Mitre link : CVE-2005-1235
JSON object : View
CWE
Products Affected
phpbb_group
- phpbb-auction