Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4872

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2007-4872
Last Modified 03 Aug 2013 02:28:48
Published 27 Sep 2007 03:17:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-4872

Summary

SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages.

Vulnerable Systems

Application

  • Simplenews 2.41.03


References

BUGTRAQ - 20070925 SimpNews version 2.41.03 Multiple Path Disclosure Vulnerabilities

MISC - http://www.netvigilance.com/advisory0068

OSVDB - 43543

OSVDB - 43542

OSVDB - 43541

OSVDB - 43540

CONFIRM - http://forum.boesch-it.de/viewtopic.php?t=2791

XF - simpnews-multiple-information-disclosure(36779)

SREASON - 3174


Last Updated: 27 May 2016 10:45:58