Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2381

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2005-2381
Last Modified 05 Sep 2008 04:51:36
Published 26 Jul 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-2381

Summary

PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to dumpquestion.php, or an invalid lid parameter to (9) labels.php or (10) dumplabel.php, which reveal the path in an error message.

Vulnerable Systems

Application

  • Php Surveyor 0.98


References

BUGTRAQ - 20050720 Multiple Vulnerabilities in PHP Surveyor

SECUNIA - 16123


Last Updated: 27 May 2016 10:40:30