First published: Thu Nov 01 2007(Updated: )
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5774 is considered a moderate severity vulnerability due to its potential for disclosing sensitive information.
To fix CVE-2007-5774, ensure you validate and sanitize input parameters in the File Manager module to prevent revealing sensitive paths.
CVE-2007-5774 enables remote attackers to perform information disclosure attacks by exploiting invalid parameters.
CVE-2007-5774 affects Flatnuke 3 and potentially earlier versions of this software.
Yes, the information disclosed by CVE-2007-5774 can potentially be leveraged for further attacks on the system.