CVE-2010-2859: Infoleak
Published Jul 23, 2010
·Updated
news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.
Affected Software
32 affected components
Boesch-it Simpnews=2.42.0
Boesch-it Simpnews=2.13
Boesch-it Simpnews=2.30.6
Boesch-it Simpnews=2.41.0
Boesch-it Simpnews=2.32.1
Boesch-it Simpnews=2.42.01
Boesch-it Simpnews=2.33.01
Boesch-it Simpnews=2.39.0
Boesch-it Simpnews=2.38.03
Boesch-it Simpnews=2.41.03
Boesch-it Simpnews=2.34.01
Boesch-it Simpnews=2.30
Boesch-it Simpnews=2.47.00
Boesch-it Simpnews=2.38.04
Boesch-it Simpnews=2.34
Boesch-it Simpnews=2.33.0
Boesch-it Simpnews=2.40.01
Boesch-it Simpnews=2.34.0
Boesch-it Simpnews=2.36.00
Boesch-it Simpnews=2.37.02
Boesch-it Simpnews=2.31.0
Boesch-it Simpnews<=2.47.03
Boesch-it Simpnews=2.41.02
Boesch-it Simpnews=2.37.00
Boesch-it Simpnews=2.38
Boesch-it Simpnews=2.44.00
Boesch-it Simpnews=2.32.0
Boesch-it Simpnews=2.35.00
Boesch-it Simpnews=2.38.02
Boesch-it Simpnews=2.0.1
Boesch-it Simpnews=2.37.01
Boesch-it Simpnews=2.30.2
Event History
Jul 23, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2859?
CVE-2010-2859 is classified as a medium severity vulnerability due to its ability to expose sensitive information.
2
How do I fix CVE-2010-2859?
To fix CVE-2010-2859, upgrade to SimpNews version 2.47.3 or later where the vulnerability is addressed.
3
What is affected by CVE-2010-2859?
CVE-2010-2859 affects SimpNews versions 2.42.0 and earlier, including multiple specific versions up to 2.47.00.
4
What type of vulnerability is CVE-2010-2859?
CVE-2010-2859 is an information disclosure vulnerability that reveals installation paths through error messages.
5
Can CVE-2010-2859 allow remote attacks?
Yes, CVE-2010-2859 can be exploited by remote attackers to obtain sensitive information through an invalid lang parameter.