First published: Fri Dec 31 2004(Updated: )
Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XMB Forum | =1.9_nexus_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2588 is classified as a medium severity vulnerability due to its potential for information disclosure.
To fix CVE-2004-2588, you should disable or restrict access to the phpinfo.php file in XMB Forum 1.9 Nexus Beta.
CVE-2004-2588 can leak sensitive information about the web server configuration and PHP application settings.
CVE-2004-2588 affects users of XMB Forum version 1.9 Nexus Beta.
Yes, CVE-2004-2588 can be exploited remotely by attackers without authentication.