CVE-2007-0385: High severity Postnuke Software Foundation Postnuke vulnerability
Published Jan 19, 2007
·Updated
The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined idcat variable.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke=0.764
Event History
Jan 19, 2007
CVE Published
11:28 PM
Jan 20, 2007
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0385?
The severity of CVE-2007-0385 is classified as moderate due to the potential exposure of sensitive information.
2
How do I fix CVE-2007-0385?
To fix CVE-2007-0385, update to the latest version of PostNuke that addresses the vulnerabilities associated with unvalidated output.
3
What type of information can be disclosed by CVE-2007-0385?
CVE-2007-0385 can allow remote attackers to disclose sensitive information such as the full path of the server.
4
Which versions of PostNuke are affected by CVE-2007-0385?
CVE-2007-0385 affects PostNuke version 0.764.
5
Is CVE-2007-0385 a local or remote vulnerability?
CVE-2007-0385 is a remote vulnerability that allows attackers to exploit it from outside the affected system.