CVE-2007-5130: Input Validation
Published Sep 27, 2007
·Updated
SimpGB 1.46.02 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php or (2) a direct request to admin/trailer.php, which reveals the path in various error messages.
Affected Software
1 affected component
Boesch-it Simpgb=1.46.02
Remediation
Patch Available
Event History
Sep 27, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5130?
CVE-2007-5130 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2007-5130?
To fix CVE-2007-5130, update to a later version of SimpGB that addresses this vulnerability.
3
What types of sensitive information can be exposed by CVE-2007-5130?
CVE-2007-5130 can expose sensitive information such as server paths through error messages.
4
Can CVE-2007-5130 be exploited without authentication?
Yes, CVE-2007-5130 can be exploited by remote attackers without requiring authentication.
5
Which versions of SimpGB are affected by CVE-2007-5130?
CVE-2007-5130 affects SimpGB version 1.46.02.