The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.
References
Configurations
History
No history.
Information
Published : 2007-01-19 23:28
Updated : 2024-02-28 11:01
NVD link : CVE-2007-0385
Mitre link : CVE-2007-0385
CVE.ORG link : CVE-2007-0385
JSON object : View
Products Affected
postnuke_software_foundation
- postnuke
CWE