Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2325

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2005-2325
Last Modified 05 Sep 2008 04:51:28
Published 19 Jul 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-2325

Summary

Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5) randomhlinesblock.php, (6) showlast.php, (7) showlast5class1.php, (8) showlast5phorum.php, (9) showlast5phorumblock.php, (10) showlastforumbb2.php, or (11) showlastforumbb2block.php.

Vulnerable Systems

Application

  • Clever Copy 2.0

  • Clever Copy 2.0a


References

MISC - http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html


Last Updated: 27 May 2016 10:40:28