ClaSS 'scripts/export.php' Information Disclosure Vulnerability
BID:32929
Info
ClaSS 'scripts/export.php' Information Disclosure Vulnerability
| Bugtraq ID: | 32929 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5856 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2008 12:00AM |
| Updated: | Apr 13 2015 08:10PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
ClaSS ClaSS 0.8.60 |
| Not Vulnerable: |
ClaSS ClaSS 0.8.61 |
Discussion
ClaSS 'scripts/export.php' Information Disclosure Vulnerability
ClaSS is prone to a information-disclosure vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Versions prior to ClaSS 0.8.61 are vulnerable.
ClaSS is prone to a information-disclosure vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Versions prior to ClaSS 0.8.61 are vulnerable.
Exploit / POC
ClaSS 'scripts/export.php' Information Disclosure Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
ClaSS 'scripts/export.php' Information Disclosure Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
ClaSS 'scripts/export.php' Information Disclosure Vulnerability
References:
References:
- ClaSS 0.8.61 Release Notes (ClaSS)
- ClaSS Homepage (ClaSS)