CVE-2006-1677: Infoleak
Published Apr 10, 2006
·Updated
MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to includes/legacy.php.
Affected Software
3 affected components
MAXdev MD-Pro<=1.0.75
MAXdev MD-Pro=1.0.72
MAXdev MD-Pro=1.0.73
Event History
Apr 11, 2006
CVE Published
via NVD·12:02 AM
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1677?
CVE-2006-1677 is classified as a medium severity vulnerability due to the exposure of sensitive file path information.
2
How do I fix CVE-2006-1677?
To fix CVE-2006-1677, upgrade MAXdev MDPro to version 1.0.76 or later, which addresses this vulnerability.
3
What versions of MAXdev MDPro are affected by CVE-2006-1677?
MAXdev MDPro versions 1.0.72 and 1.0.73, and possibly other versions prior to 1.0.76, are affected by CVE-2006-1677.
4
What is the attack vector for CVE-2006-1677?
CVE-2006-1677 can be exploited by remote attackers through a direct request to the legacy.php file.
5
What information can be exposed by CVE-2006-1677?
CVE-2006-1677 allows attackers to obtain the full path of the server when the vulnerability is exploited.