Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=111893777504821&w=2 | |
http://secunia.com/advisories/15732 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=111893777504821&w=2 | |
http://secunia.com/advisories/15732 | Patch Vendor Advisory |
Configurations
History
20 Nov 2024, 23:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=111893777504821&w=2 - | |
References | () http://secunia.com/advisories/15732 - Patch, Vendor Advisory |
Information
Published : 2005-06-16 04:00
Updated : 2024-11-20 23:58
NVD link : CVE-2005-2003
Mitre link : CVE-2005-2003
CVE.ORG link : CVE-2005-2003
JSON object : View
Products Affected
ultimate_php_board
- ultimate_php_board
CWE