CVE-2006-3938
Summary
| CVE | CVE-2006-3938 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-31 22:04:00 UTC |
| Updated | 2018-10-17 21:32:00 UTC |
| Description | DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrire/tools/blogroll/; (4) syslog/index.php, (5) thememng/index.php, (6) toolsmng/index.php, (7) utf8convert/index.php in /ecrire/tools/; (8) /ecrire/inc/connexion.php and (9) /inc/session.php; (10) class.blog.php, (11) class.blogcomment.php, (12) and class.blogpost.php in /inc/classes/; (13) append.php, (14) class.xblog.php, (15) class.xblogcomment.php, and (16) class.xblogpost.php in /layout/; (17) form.php, (18) list.php, (19) post.php, or (20) template.php in /themes/default/, which reveal the installation path in error messages. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dotclear | Dotclear | 1.2.1 | All | All | All |
| Application | Dotclear | Dotclear | 1.2.2 | All | All | All |
| Application | Dotclear | Dotclear | 1.2.3 | All | All | All |
| Application | Dotclear | Dotclear | 1.2.4 | All | All | All |
| Application | Dotclear | Dotclear | 1.2.1 | All | All | All |
| Application | Dotclear | Dotclear | 1.2.2 | All | All | All |
| Application | Dotclear | Dotclear | 1.2.3 | All | All | All |
| Application | Dotclear | Dotclear | 1.2.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 29822 | OSVDB | www.osvdb.org | |
| 29831 | OSVDB | www.osvdb.org | |
| 29825 | OSVDB | www.osvdb.org | |
| 29817 | OSVDB | www.osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 29829 | OSVDB | www.osvdb.org | |
| 29820 | OSVDB | www.osvdb.org | |
| 29812 | OSVDB | www.osvdb.org | |
| 29827 | OSVDB | www.osvdb.org | |
| 29815 | OSVDB | www.osvdb.org | |
| 29818 | OSVDB | www.osvdb.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| DotClear : Multiples Full Path Disclosure - SecurityReason.com | SREASON | securityreason.com | |
| 29824 | OSVDB | www.osvdb.org | |
| 29816 | OSVDB | www.osvdb.org | |
| 29823 | OSVDB | www.osvdb.org | |
| 29830 | OSVDB | www.osvdb.org | |
| 29826 | OSVDB | www.osvdb.org | |
| 29814 | OSVDB | www.osvdb.org | |
| 29821 | OSVDB | www.osvdb.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 29813 | OSVDB | www.osvdb.org | |
| 29828 | OSVDB | www.osvdb.org | |
| Free Pages Personnelles: Erreur 500 - Erreur interne du serveur | MISC | zone14.free.fr | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.