First published: Wed Nov 14 2007(Updated: )
Bandersnatch 0.4 allows remote attackers to obtain sensitive information via a malformed request for index.php with (1) a certain func parameter value; or (2) certain func, jid, page, and limit parameter values; which reveals the path in various error messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jason Alexander phNNTP | =0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5942 is classified as a moderate severity vulnerability due to its potential for information leakage.
To mitigate CVE-2007-5942, ensure that the application is upgraded or patched to a secure version that addresses this vulnerability.
CVE-2007-5942 allows remote attackers to exploit the vulnerability and obtain sensitive information through malformed requests.
CVE-2007-5942 affects Bandersnatch version 0.4.
CVE-2007-5942 can disclose sensitive path information through error messages when specific request parameters are used.