First published: Thu Feb 10 2005(Updated: )
Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exponent Exponent | =0.95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0310 is categorized as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2005-0310, upgrade Exponent to a patched version or implement access controls to restrict direct HTTP requests to vulnerable files.
CVE-2005-0310 specifically affects Exponent version 0.95.
CVE-2005-0310 is an information disclosure vulnerability that allows unauthorized access to sensitive data.
CVE-2005-0310 affects the following files: search.info.php, permissions.info.php, security.info.php, formcontrol.php, and file_modules.php.