First published: Tue Mar 22 2005(Updated: )
Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive information via an invalid parameter to the convertorderbytrans function, which reveals the path in a PHP error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =1.1a | |
E-xoops | =1.05_rev3 | |
Ciamos CMS | =0.9.2_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0827 is classified as a medium severity vulnerability due to its potential for information disclosure.
To fix CVE-2005-0827, you should update the affected software to the latest version that addresses this vulnerability.
CVE-2005-0827 affects RUNCMS 1.1A, Ciamos 0.9.2 RC1, and e-Xoops 1.05 Rev3.
CVE-2005-0827 allows remote attackers to obtain sensitive information, specifically the server path via PHP error messages.
Yes, CVE-2005-0827 can be exploited by remote attackers through an invalid parameter sent to the vulnerable function.