First published: Thu May 04 2006(Updated: )
RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Request Tracker | =3.5.head |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2169 is rated as a medium severity vulnerability as it allows attackers to disclose sensitive information.
To mitigate CVE-2006-2169, ensure that Request Tracker is updated to a secure version or restrict access to the Dist/Display.html page.
CVE-2006-2169 can expose the installation path of the Request Tracker software in error messages.
CVE-2006-2169 affects users running Request Tracker version 3.5.HEAD.
Yes, the exposure of installation paths due to CVE-2006-2169 may assist attackers in conducting more targeted attacks.