Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=111893777504821&w=2 | |
http://secunia.com/advisories/15732 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2005-06-16 04:00
Updated : 2016-10-18 03:23
NVD link : CVE-2005-2003
Mitre link : CVE-2005-2003
CVE.ORG link : CVE-2005-2003
JSON object : View
Products Affected
ultimate_php_board
- ultimate_php_board
CWE