CVE Vulnerabilities

CVE-2004-2362

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, which leaks the pathname in a database error message, as demonstrated using forums.php.

Affected Software

Name Vendor Start Version End Version
Phpx Phpx 1.0.7 1.0.7
Phpx Phpx 1.0.10 1.0.10
Phpx Phpx 1.0.14 1.0.14
Phpx Phpx 2.1.0 2.1.0
Phpx Phpx 2.2.0 2.2.0
Phpx Phpx 2.2.1 2.2.1
Phpx Phpx 2.2.3 2.2.3
Phpx Phpx 2.2.4 2.2.4
Phpx Phpx 3.0.0 3.0.0
Phpx Phpx 3.0.1 3.0.1
Phpx Phpx 3.0.2 3.0.2
Phpx Phpx 3.0.3 3.0.3
Phpx Phpx 3.0.4 3.0.4
Phpx Phpx 3.0.5 3.0.5
Phpx Phpx 3.0.6 3.0.6
Phpx Phpx 3.0.7 3.0.7
Phpx Phpx 3.1.0 3.1.0
Phpx Phpx 3.1.1 3.1.1
Phpx Phpx 3.1.2 3.1.2
Phpx Phpx 3.1.3 3.1.3
Phpx Phpx 3.1.4 3.1.4
Phpx Phpx 3.2.0 3.2.0
Phpx Phpx 3.2.1 3.2.1
Phpx Phpx 3.2.2 3.2.2
Phpx Phpx 3.2.3 3.2.3
Phpx Phpx 3.2.4 3.2.4
Phpx Phpx 3.2.5 3.2.5
Phpx Phpx 3.2.6 3.2.6

References