Beveiligingsadvies

CVE-2009-0674

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2009-02-22 22:00:00
Laatst bijgewerkt 2024-08-07 04:40:05
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames.