Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35v9-54h8-hx2c

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.

EPSS

Процентиль: 49%
0.00258
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 19 лет назад

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.

EPSS

Процентиль: 49%
0.00258
Низкий

Дефекты

CWE-200