First published: Fri Sep 23 2005(Updated: )
PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3050 has a moderate severity level due to its potential for information disclosure.
To fix CVE-2005-3050, upgrade phpMyFAQ to a version later than 1.5.1 which addresses this vulnerability.
The impact of CVE-2005-3050 is that it allows remote attackers to obtain sensitive file path information from the server.
CVE-2005-3050 specifically affects phpMyFAQ version 1.5.1.
To mitigate risk from CVE-2005-3050, ensure that sensitive information is not exposed through error messages and consider implementing additional access controls.