CVE-2007-4072: Medium severity Tincan Webbler Cms vulnerability
Published Jul 30, 2007
·Updated
Webbler CMS before 3.1.6 provides the full installation path within HTML comments in certain documents, which allows remote attackers to obtain sensitive information by viewing the HTML source, as demonstrated by viewing the source generated from index.php.
Affected Software
1 affected component
Tincan Webbler Cms<=3.1.4
Remediation
Patch Available
Event History
Jul 30, 2007
CVE Published
05:30 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4072?
CVE-2007-4072 has a medium severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2007-4072?
To fix CVE-2007-4072, upgrade Webbler CMS to version 3.1.6 or later.
3
What kind of information can be exposed by CVE-2007-4072?
CVE-2007-4072 can expose the full installation path of the Webbler CMS in HTML comments.
4
Is CVE-2007-4072 exploitable remotely?
Yes, CVE-2007-4072 can be exploited remotely by accessing the HTML source of affected documents.
5
Which versions of Webbler CMS are affected by CVE-2007-4072?
Webbler CMS versions prior to 3.1.6, including 3.1.4 and below, are affected by CVE-2007-4072.