CVE-2005-2474

ChurchInfo allows remote attackers to execute obtain sensitive information via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, an invalid Number parameter to (8) SelectList.php or (9) SelectDelete.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php, which reveal the path in an error message.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:churchinfo:churchinfo:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:churchinfo:churchinfo:1.1.6:*:*:*:*:*:*:*

Information

Published : 2005-08-04 21:00

Updated : 2017-07-10 18:32


NVD link : CVE-2005-2474

Mitre link : CVE-2005-2474


JSON object : View

Advertisement

dedicated server usa

Products Affected

churchinfo

  • churchinfo