5

CVE-2007-4861

SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QuirmSaxon Version5.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.81% 0.759
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://osvdb.org/45330
http://osvdb.org/45331
http://osvdb.org/45332
http://osvdb.org/45333
http://osvdb.org/45334
http://securityreason.com/securityalert/3311
http://www.netvigilance.com/advisory0053
http://www.quirm.net/punbb/viewtopic.php?id=129
http://www.securityfocus.com/archive/1/482930/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/38138