First published: Thu Feb 02 2006(Updated: )
SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Spip | <=1.9_alpha2_5539 | |
Spip | <=1.8.2e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0519 is considered to have a medium severity level as it allows leakage of sensitive information.
To fix CVE-2006-0519, upgrade SPIP to version 1.9 Alpha 3 or later or apply appropriate patches.
CVE-2006-0519 can be exploited by remote attackers to gain unauthorized access to the file paths on the server.
CVE-2006-0519 affects SPIP versions 1.8.2-e and earlier as well as 1.9 Alpha 2 and earlier.
The potential impacts of CVE-2006-0519 include exposing sensitive information that could aid in further attacks.