CVE-2005-1235: Medium severity Phpbb Group Phpbb-auction vulnerability
Published Apr 24, 2005
·Updated
auctionmyauctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
Affected Software
2 affected components
Phpbb Group Phpbb-auction=1.2m
Phpbb Group Phpbb-auction=1.0m
Remediation
Patch Available
Event History
Apr 24, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1235?
CVE-2005-1235 is considered to have a low severity as it only exposes the full path in a PHP error message.
2
How do I fix CVE-2005-1235?
To mitigate CVE-2005-1235, update phpbb-Auction to version 1.2n or later, which addresses this vulnerability.
3
What are the affected versions in CVE-2005-1235?
The affected versions of phpbb-Auction are 1.0m and 1.2m.
4
What type of attack is associated with CVE-2005-1235?
CVE-2005-1235 allows remote attackers to exploit the application through an invalid mode parameter.
5
What information is leaked by CVE-2005-1235?
CVE-2005-1235 leaks sensitive information by disclosing the full path of the PHP application in error messages.