Описание
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:black_tie_project:black_tie_project:0.4b:*:*:*:*:*:*:*
cpe:2.3:a:black_tie_project:black_tie_project:0.5:*:*:*:*:*:*:*
cpe:2.3:a:black_tie_project:black_tie_project:0.5b:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00808
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message.
EPSS
Процентиль: 74%
0.00808
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other