Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-4257

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2012-4257
Last Modified 14 Aug 2012 12:00:00
Published 13 Aug 2012 02:55:05
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-4257

Summary

Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message.

Vulnerable Systems

Application

  • George Karpouzas Yet Another Question %26 Answer System 1.0


References

XF - yaqas-index-info-disclosure(75205)

MISC - http://packetstormsecurity.org/files/112248/Yaqas-CMS-Alpha1-Information-Disclosure.html

MISC - http://hauntit.blogspot.com/2012/03/en-yaqas-cms-alpha1-information.html


Last Updated: 27 May 2016 10:51:40