CVE-2004-0355: Medium severity Invision Power Services Invision Board vulnerability
Published Mar 18, 2004
·Updated
Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.
Affected Software
1 affected component
Invision Power Services Invision Board=1.3
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0355?
CVE-2004-0355 has a medium severity rating as it can expose sensitive information to remote attackers.
2
How do I fix CVE-2004-0355?
To fix CVE-2004-0355, ensure that only image files can be uploaded for the 'Personal Photo' feature.
3
What types of files can exploit CVE-2004-0355?
CVE-2004-0355 can be exploited by selecting non-image files, which can trigger error messages showing sensitive installation paths.
4
Who is affected by CVE-2004-0355?
Users of Invision Power Board 1.3 Final are affected by CVE-2004-0355.
5
What is the impact of CVE-2004-0355?
The impact of CVE-2004-0355 includes potential exposure of the web server's installation path to unauthorized users.