CVE-2001-1437

easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.
Configurations

Configuration 1 (hide)

cpe:2.3:a:easyscripts:easynews:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:37

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html - Exploit () http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html - Exploit
References () http://www.kb.cert.org/vuls/id/597795 - US Government Resource () http://www.kb.cert.org/vuls/id/597795 - US Government Resource
References () http://www.securityfocus.com/bid/3649 - Exploit () http://www.securityfocus.com/bid/3649 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/7660 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/7660 -

Information

Published : 2001-12-01 05:00

Updated : 2024-11-20 23:37


NVD link : CVE-2001-1437

Mitre link : CVE-2001-1437

CVE.ORG link : CVE-2001-1437


JSON object : View

Products Affected

easyscripts

  • easynews