Description
Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably resultant from another issue in functions.php.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-2552 | Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably resultant from another issue in functions.php. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T17:51:04.951Z
Reserved: 2006-05-23T00:00:00.000Z
Link: CVE-2006-2552
No data.
Status : Modified
Published: 2006-05-24T01:02:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-2552
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD