index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.
References
Link | Resource |
---|---|
https://gist.github.com/nenf/2f16cd547c2afe166d1cb3f88f18bf81 | Third Party Advisory |
https://gist.github.com/nenf/2f16cd547c2afe166d1cb3f88f18bf81 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:48
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/nenf/2f16cd547c2afe166d1cb3f88f18bf81 - Third Party Advisory |
Information
Published : 2019-02-07 16:29
Updated : 2024-11-21 04:48
NVD link : CVE-2019-7535
Mitre link : CVE-2019-7535
CVE.ORG link : CVE-2019-7535
JSON object : View
Products Affected
gurock
- testrail
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor