XOOPS XoopsOption Information Disclosure Vulnerability
BID:7149
Info
XOOPS XoopsOption Information Disclosure Vulnerability
| Bugtraq ID: | 7149 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2003 12:00AM |
| Updated: | Mar 20 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Gregory Le Bras" <[email protected]>. |
| Vulnerable: |
Xoops Xoops 2.0 |
| Not Vulnerable: | |
Discussion
XOOPS XoopsOption Information Disclosure Vulnerability
XOOPS has been reported vulnerable to an information disclosure vulnerability. According to the report, path information and other sensitive data may be output in server error messages. Information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system. This vulnerability was reported to affect XOOPS version 2.0. It is not currently known if other versions are affected.
XOOPS has been reported vulnerable to an information disclosure vulnerability. According to the report, path information and other sensitive data may be output in server error messages. Information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system. This vulnerability was reported to affect XOOPS version 2.0. It is not currently known if other versions are affected.
Solution / Fix
XOOPS XoopsOption Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
XOOPS XoopsOption Information Disclosure Vulnerability
References:
References:
- [Full-Disclosure] [SCSA-011] Path Disclosure Vulnerability in XOOPS ("Gregory Le Bras"
) - ProManager Homepage (Promanager)
- Re: [SCSA-011] Path Disclosure Vulnerability in XOOPS ("Grégory" Le Bras
)