CVE-2006-6267: High severity Postnuke Software Foundation Postnuke vulnerability
Published Dec 4, 2006
·Updated
PostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke=0.7.5.0
Event History
Dec 4, 2006
CVE Published
11:28 AM
Data Sourced
via NVD·11:28 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6267?
CVE-2006-6267 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2006-6267?
To mitigate CVE-2006-6267, update PostNuke to a version higher than 0.7.5.0 that addresses this vulnerability.
3
What systems are affected by CVE-2006-6267?
CVE-2006-6267 affects PostNuke version 0.7.5.0 and certain minor versions.
4
What kind of information can be exposed by CVE-2006-6267?
CVE-2006-6267 can expose the file path through an error message when a non-numeric value is passed as the stop parameter.
5
Is CVE-2006-6267 still relevant today?
While CVE-2006-6267 is an older vulnerability, it remains relevant for organizations still using affected versions of PostNuke.