Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.
References
Link | Resource |
---|---|
http://secunia.com/advisories/15732 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=111893777504821&w=2 |
Configurations
Information
Published : 2005-06-15 21:00
Updated : 2016-10-17 20:23
NVD link : CVE-2005-2003
Mitre link : CVE-2005-2003
JSON object : View
CWE
Products Affected
ultimate_php_board
- ultimate_php_board