search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive information via invalid (1) datestart and (2) dateend parameters, which leaks the web server path in an error message.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-12-05T11:00:00
Updated: 2024-08-07T23:31:48.967Z
Reserved: 2005-12-05T00:00:00
Link: CVE-2005-4026
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-12-05T11:03:00.000
Modified: 2024-11-21T00:03:19.283
Link: CVE-2005-4026
Redhat
No data.