CVE Vulnerabilities

CVE-2005-4026

Published: Dec 05, 2005 | Modified: Sep 27, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive information via invalid (1) datestart and (2) dateend parameters, which leaks the web server path in an error message.

Affected Software

Name Vendor Start Version End Version
Geeklog Geeklog 1.3.0 (including) 1.3.11 (including)
Geeklog Geeklog 1.3.11-rc1 (including) 1.3.11-rc1 (including)
Geeklog Geeklog 1.3.11-sr1 (including) 1.3.11-sr1 (including)
Geeklog Geeklog 1.3.11-sr2 (including) 1.3.11-sr2 (including)
Geeklog Geeklog 1.4.0-beta1 (including) 1.4.0-beta1 (including)

References