Markus Triska CGINews and CGIForum Information Disclosure Vulnerability
BID:9214
Info
Markus Triska CGINews and CGIForum Information Disclosure Vulnerability
| Bugtraq ID: | 9214 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2003 12:00AM |
| Updated: | Dec 15 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to GulfTech Security Research Team <http://www.gulftech.org>. |
| Vulnerable: |
Markus Triska CGINews 1.0.7 Markus Triska CGIForum 1.0.9 |
| Not Vulnerable: | |
Discussion
Markus Triska CGINews and CGIForum Information Disclosure Vulnerability
It has been reported that CGINews and CGIForum may be prone to an information disclosure vulnerability that may allow an attacker to gain access to sensitive information such as usernames and e-mail addresses. The problem exists because the log files 'username.log' are viewable by any user.
CGINews versions 1.07 and CGIForum 1.09 are reported to be vulnerable to this issue, however other versions could be affected as well.
It has been reported that CGINews and CGIForum may be prone to an information disclosure vulnerability that may allow an attacker to gain access to sensitive information such as usernames and e-mail addresses. The problem exists because the log files 'username.log' are viewable by any user.
CGINews versions 1.07 and CGIForum 1.09 are reported to be vulnerable to this issue, however other versions could be affected as well.
Exploit / POC
Solution / Fix
References
Markus Triska CGINews and CGIForum Information Disclosure Vulnerability
References:
References:
- Product Homepage (Markus Triska)
- Issues In CGINews and CGIForum (JeiAr
)