Zope addItems Script Information Disclosure Vulnerability
BID:7999
Info
Zope addItems Script Information Disclosure Vulnerability
| Bugtraq ID: | 7999 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2003 12:00AM |
| Updated: | Jun 20 2003 12:00AM |
| Credit: | This issue was reported by "morning_wood" <[email protected]>. |
| Vulnerable: |
Zope Zope 2.6.1 Zope Zope 2.5.1 |
| Not Vulnerable: | |
Discussion
Zope addItems Script Information Disclosure Vulnerability
A vulnerability has been discovered in Zope which may result in the disclosure of sensitive information to a remote attacker. The problem occurs when a value of excessive size is passed as a URI parameter to the addItems script. When this occurs, an exception will be triggered causing the server to return an error page containing sensitive system information.
Access to this information could potentially aid an attacker in launching further attacks against the system.
A vulnerability has been discovered in Zope which may result in the disclosure of sensitive information to a remote attacker. The problem occurs when a value of excessive size is passed as a URI parameter to the addItems script. When this occurs, an exception will be triggered causing the server to return an error page containing sensitive system information.
Access to this information could potentially aid an attacker in launching further attacks against the system.
Exploit / POC
Zope addItems Script Information Disclosure Vulnerability
No exploit is required.
No exploit is required.