First published: Sat May 29 2004(Updated: )
e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.6_15 | |
e107 CMS | =0.6_15a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2039 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
To fix CVE-2004-2039, upgrade to a version of e107 that is not affected, ideally newer than 0.6_15a.
CVE-2004-2039 is an information disclosure vulnerability that allows attackers to obtain sensitive information.
CVE-2004-2039 affects e107 CMS versions 0.6_15 and 0.6_15a.
Through CVE-2004-2039, attackers can disclose the full server path via PHP error messages.