CVE Vulnerabilities

CVE-2005-3763

Published: Nov 22, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtain sensitive information. NOTE: this might be resultant from an absolute path traversal vulnerability.

Affected Software

NameVendorStart VersionEnd Version
ExponentExponent0.94 (including)0.94 (including)
ExponentExponent0.95 (including)0.95 (including)
ExponentExponent0.96.1 (including)0.96.1 (including)
ExponentExponent0.96.3 (including)0.96.3 (including)
ExponentExponent0.96.4 (including)0.96.4 (including)

References