Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6p7-6qjc-9m48

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.

miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.

EPSS

Процентиль: 90%
0.05896
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 18 лет назад

miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.

EPSS

Процентиль: 90%
0.05896
Низкий

Дефекты

CWE-200