CVE Vulnerabilities

CVE-2007-1102

Published: Feb 26, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Photostand 1.2.0 allows remote attackers to obtain sensitive information via a (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.

Affected Software

Name Vendor Start Version End Version
Photostand Photostand 1.2.0 (including) 1.2.0 (including)

References