CVE-2007-5444: Infoleak
Published Oct 14, 2007
·Updated
CMS Made Simple 1.1.3.1 allows remote attackers to obtain the full path via a direct request for unspecified files.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=1.1.3.1
Event History
Oct 14, 2007
CVE Published
06:17 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5444?
CVE-2007-5444 is classified as a medium severity vulnerability due to its potential to disclose sensitive information.
2
How do I fix CVE-2007-5444?
To fix CVE-2007-5444, upgrade to a version of CMS Made Simple that is not affected by this vulnerability.
3
What type of attack does CVE-2007-5444 enable?
CVE-2007-5444 enables remote attackers to possibly obtain sensitive information such as the full file path on the server.
4
Which version of CMS Made Simple is affected by CVE-2007-5444?
CVE-2007-5444 specifically affects CMS Made Simple version 1.1.3.1.
5
Can CVE-2007-5444 lead to further exploits?
Yes, CVE-2007-5444 can potentially lead to further exploits if attackers gain knowledge of the server's directory structure.