FreeMarker Template Name Information Disclosure Vulnerability
BID:47907
Info
FreeMarker Template Name Information Disclosure Vulnerability
| Bugtraq ID: | 47907 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2011 12:00AM |
| Updated: | May 18 2011 12:00AM |
| Credit: | Vendor |
| Vulnerable: |
FreeMarker FreeMarker 2.3.16 FreeMarker FreeMarker 2.3 |
| Not Vulnerable: |
FreeMarker FreeMarker 2.3.17 |
Discussion
FreeMarker Template Name Information Disclosure Vulnerability
FreeMarker is prone to an information-disclosure vulnerability because it fails to sufficiently sanitize user-supplied input.
Successfully exploiting this issue will allow an attacker to load arbitrary template files from the local system. Information harvested may aid in launching further attacks.
FreeMarker versions prior to 2.3.17 are affected.
FreeMarker is prone to an information-disclosure vulnerability because it fails to sufficiently sanitize user-supplied input.
Successfully exploiting this issue will allow an attacker to load arbitrary template files from the local system. Information harvested may aid in launching further attacks.
FreeMarker versions prior to 2.3.17 are affected.
Exploit / POC
FreeMarker Template Name Information Disclosure Vulnerability
An attacker can exploit this issue with a web browser.
An attacker can exploit this issue with a web browser.
Solution / Fix
FreeMarker Template Name Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
FreeMarker Template Name Information Disclosure Vulnerability
References:
References:
- FreeMarker Home page (FreeMarker)
- Fixes on FreeMarker 2.3.17 (FreeMarker)