fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2006-03-09 12:02
Updated : 2018-10-18 09:30
NVD link : CVE-2006-1119
Mitre link : CVE-2006-1119
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cpanel
- cpanel
netenberg
- fantastico_de_luxe