CVE-2008-7212: Medium severity postnuke software foundation pnphpbb vulnerability
MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tinymce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7212?
CVE-2008-7212 is considered a medium severity vulnerability due to the potential for information leakage.
How do I fix CVE-2008-7212?
To mitigate CVE-2008-7212, upgrade to Mambo version 4.6.4 or later, which addresses the vulnerability.
What type of information is exposed by CVE-2008-7212?
CVE-2008-7212 exposes sensitive information such as the installation path of the application.
Which software versions are affected by CVE-2008-7212?
CVE-2008-7212 affects Mambo versions 4.6.3 and earlier, as well as most versions of MOStlyCE up to 2.0.
Is there a workaround for CVE-2008-7212 if I cannot update?
A possible workaround for CVE-2008-7212 is to restrict access to the vulnerable PHP file based on IP or user credentials.