| |
Vulnerability CVE-2005-0655
Published: 2005-05-02 Modified: 2012-02-12
Description: |
auraCMS 1.5 allows remote attackers to obtain sensitive information via an HTTP request with an invalid id parameter to (1) teman.php, (2) hal.php, or (3) arsip.php, which reveals the path in a PHP error message. |
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5/10 |
2.9/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
http://securitytracker.com/id?1013357
http://marc.theaimsgroup.com/?l=bugtraq&m=110979842315750&w=2
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|