LifeType Unspecified Parameter Handling Information Disclosure Vulnerability
BID:22572
Info
LifeType Unspecified Parameter Handling Information Disclosure Vulnerability
| Bugtraq ID: | 22572 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0979 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2007 12:00AM |
| Updated: | Nov 04 2008 01:45AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
LifeType LifeType 1.1.5 LifeType LifeType 1.1.4 LifeType LifeType 1.1.3 LifeType LifeType 1.0.6 LifeType LifeType 1.0.5 LifeType LifeType 1.0.4 LifeType LifeType 1.0.3 LifeType LifeType 1.0.2 LifeType LifeType 1.2-beta1 LifeType LifeType 1.1 |
| Not Vulnerable: |
LifeType LifeType 1.1.6 LifeType LifeType 1.2-beta2 |
Discussion
LifeType Unspecified Parameter Handling Information Disclosure Vulnerability
LifeType is prone to an information-disclosure vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve the contents of arbitrary files in the context of the webserver process. Information obtained may aid in further attacks.
LifeType is prone to an information-disclosure vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve the contents of arbitrary files in the context of the webserver process. Information obtained may aid in further attacks.
Exploit / POC
LifeType Unspecified Parameter Handling Information Disclosure Vulnerability
An attacker can exploit this issue by using a web browser.
An attacker can exploit this issue by using a web browser.
Solution / Fix
LifeType Unspecified Parameter Handling Information Disclosure Vulnerability
Solution:
The vendor has released updates to address this issue.
LifeType LifeType 1.1
LifeType LifeType 1.0.2
LifeType LifeType 1.0.3
LifeType LifeType 1.0.4
LifeType LifeType 1.0.5
LifeType LifeType 1.0.6
LifeType LifeType 1.1.3
LifeType LifeType 1.1.4
LifeType LifeType 1.1.5
Solution:
The vendor has released updates to address this issue.
LifeType LifeType 1.1
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.0.2
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.0.3
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.0.4
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.0.5
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.0.6
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.1.3
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.1.4
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
LifeType LifeType 1.1.5
-
LifeType lifetype-1.1.6.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.1.6.tar.gz
References
LifeType Unspecified Parameter Handling Information Disclosure Vulnerability
References:
References:
- Critical security issue: Lifetype 1.1.6 and Lifetype 1.2-beta2 released (LifeType)
- LifeType Home Page (LifeType)