Description
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2005-4167 | eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T04:24:34.322Z
Reserved: 2005-12-11T00:00:00.000Z
Link: CVE-2005-4172
No data.
Status : Deferred
Published: 2005-12-11T21:03:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-4172
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD