First published: Wed Apr 25 2007(Updated: )
Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oicgroup Exponent Cms | <=0.96.6_alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2253 has a medium severity level due to the potential exposure of sensitive path information.
To fix CVE-2007-2253, upgrade to a newer version of Exponent CMS that addresses this vulnerability.
CVE-2007-2253 affects Exponent CMS version 0.96.6 Alpha and earlier.
Yes, CVE-2007-2253 allows remote attackers to exploit the vulnerability to obtain path information.
Exploiting CVE-2007-2253 could lead to potential information disclosure which can aid further attacks.