Search

published date: March 12, 2005

CVE-2005-0780 : paFileDB 3.1 and earlier...

Description

paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.

Product(s):

  • PHP Arena PaFileDB 1.1.3
  • PHP Arena PaFileDB 2.1.1
  • PHP Arena PAFileDB 3.0
  • PHP Arena PAFileDB 3.0 Beta 3.1
  • PHP Arena PAFileDB 3.1

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2005-0780, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2005-0780 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?