CVE-2008-4170: Infoleak
Published Sep 22, 2008
·Updated
createaccount.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.
Affected Software
1 affected component
osCommerce oscommerce=2.2-rc_2a
Event History
Sep 22, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4170?
CVE-2008-4170 has a medium severity rating as it allows exposure of sensitive information.
2
How do I fix CVE-2008-4170?
To fix CVE-2008-4170, upgrade to a newer version of osCommerce that addresses this vulnerability.
3
What impact does CVE-2008-4170 have on my osCommerce installation?
CVE-2008-4170 can expose your installation path to attackers, increasing the risk of further attacks.
4
What versions of osCommerce are affected by CVE-2008-4170?
CVE-2008-4170 specifically affects osCommerce version 2.2 RC 2a.
5
Can I prevent CVE-2008-4170 by changing configuration settings?
Changing configuration settings alone will not prevent CVE-2008-4170; updating to a secure version is necessary.