Описание
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:black_tie_project:black_tie_project:0.4b:*:*:*:*:*:*:*
cpe:2.3:a:black_tie_project:black_tie_project:0.5:*:*:*:*:*:*:*
cpe:2.3:a:black_tie_project:black_tie_project:0.5b:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02596
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message.
EPSS
Процентиль: 84%
0.02596
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other