[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-3938Date: (C)2006-07-31   (M)2023-12-22


DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrire/tools/blogroll/; (4) syslog/index.php, (5) thememng/index.php, (6) toolsmng/index.php, (7) utf8convert/index.php in /ecrire/tools/; (8) /ecrire/inc/connexion.php and (9) /inc/session.php; (10) class.blog.php, (11) class.blogcomment.php, (12) and class.blogpost.php in /inc/classes/; (13) append.php, (14) class.xblog.php, (15) class.xblogcomment.php, and (16) class.xblogpost.php in /layout/; (17) form.php, (18) list.php, (19) post.php, or (20) template.php in /themes/default/, which reveal the installation path in error messages.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SREASON-1307
http://www.securityfocus.com/archive/1/archive/1/440874/100/100/threaded
http://www.securityfocus.com/archive/1/archive/1/459820/100/0/threaded
OSVDB-29812
OSVDB-29813
OSVDB-29814
OSVDB-29815
OSVDB-29816
OSVDB-29817
OSVDB-29818
OSVDB-29820
OSVDB-29821
OSVDB-29822
OSVDB-29823
OSVDB-29824
OSVDB-29825
OSVDB-29826
OSVDB-29827
OSVDB-29828
OSVDB-29829
OSVDB-29830
OSVDB-29831
dotclear-multiple-path-disclosure(27913)
http://zone14.free.fr/advisories/8/

CPE    4
cpe:/a:dotclear:dotclear:1.2.3
cpe:/a:dotclear:dotclear:1.2.4
cpe:/a:dotclear:dotclear:1.2.1
cpe:/a:dotclear:dotclear:1.2.2
...

© SecPod Technologies