First published: Mon Aug 13 2012(Updated: )
The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joobi jNews | =7.5.1 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4256 has a medium severity rating due to its potential to disclose sensitive information.
To fix CVE-2012-4256, upgrade the jNews component to a version that is not vulnerable, ideally a version after 7.5.1.
CVE-2012-4256 can facilitate information disclosure attacks by exposing the Joomla installation path to remote attackers.
CVE-2012-4256 affects users of the jNews component version 7.5.1 for Joomla!.
The risk associated with CVE-2012-4256 is that sensitive directory structure information may aid attackers in further exploiting the Joomla! installation.