CVE-2005-1635: Medium severity JGS-XA JGS-Portal vulnerability
JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jgsportalref.php, (2) jgsportalland.php, (3) jgsportallog.php, (4) jgsportalglobalsponsor.php, (5) jgsportalglobal.php, (6) jgsportalsystem.php, (7) jgsportalviews.php; or multiple files in the jgsportalinclude directory, including (8) jgsportalboardmenue.php, (9) jgsportalforenliste.php, (10) jgsportalgeburtstag.php, (11) jgsportalguckloch.php, (12) jgsportalkalender.php, (13) jgsportalletztethemen.php, (14) jgsportallinks.php, (15) jgsportalneustemember.php, (16) jgsportalnewsboard.php, (17) jgsportalonline.php, (18) jgsportalpn.php, (19) jgsportalportalmenue.php, (20) jgsportalstyles.php, (21) jgsportalsuchen.php, (22) jgsportalteam.php, (23) jgsportaltopforen.php, (24) jgsportaltopposter.php, (25) jgsportalumfrage.php, (26) jgsportaluseravatar.php, (27) jgsportalwaronline.php, (28) jgsportalwoonline.php, or (29) jgsportalzufallsavatar.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1635?
CVE-2005-1635 is classified as a moderate severity vulnerability due to its potential to expose sensitive server path information.
How do I fix CVE-2005-1635?
To mitigate CVE-2005-1635, ensure that you update JGS-Portal to version 3.0.3 or later, which addresses this vulnerability.
What type of attack does CVE-2005-1635 allow?
CVE-2005-1635 allows remote attackers to conduct path disclosure attacks by exploiting specific PHP files in JGS-Portal.
Which software versions are affected by CVE-2005-1635?
CVE-2005-1635 affects JGS-Portal versions 3.0.2 and earlier.
What information can be leaked through CVE-2005-1635?
CVE-2005-1635 can leak the full server path through direct requests to certain PHP files.