spree Content Controller Remote Information Disclosure Vulnerability
BID:47612
Info
spree Content Controller Remote Information Disclosure Vulnerability
| Bugtraq ID: | 47612 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2011 12:00AM |
| Updated: | Aug 12 2015 10:28PM |
| Credit: | John Hartzler |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
spree Content Controller Remote Information Disclosure Vulnerability
spree is prone to an information-disclosure vulnerability that affects the Content Controller component.
Exploiting this issue may allow an attacker to gain access to potentially sensitive information. Information obtained may aid in further attacks.
Versions prior to spree 0.50.1 are vulnerable.
spree is prone to an information-disclosure vulnerability that affects the Content Controller component.
Exploiting this issue may allow an attacker to gain access to potentially sensitive information. Information obtained may aid in further attacks.
Versions prior to spree 0.50.1 are vulnerable.
Exploit / POC
spree Content Controller Remote Information Disclosure Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
Attackers can use readily available tools and commands to exploit this issue.
Solution / Fix
spree Content Controller Remote Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
spree Content Controller Remote Information Disclosure Vulnerability
References:
References: