Required CVE Record Information
Description
Alstrasoft Article Manager Pro 1.6 allows remote attackers to obtain sensitive information via (1) a quote character or possibly an invalid value in the action parameter in a request to mrarticles.php or (2) a login QUERY_STRING to admin.php without any additional parameters, which reveal the path in various error messages.
References 4 Total
- securityreason.com: 949 third-party-advisory
- vupen.com: ADV-2006-1943 vdb-entry
- exchange.xforce.ibmcloud.com: article-manager-multi-scripts-path-disclosure(26676) vdb-entry
- securityfocus.com: 20060522 Alstrasoft Article Manager Pro v1.6 mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityreason.com: 949 third-party-advisoryx_transferred
- vupen.com: ADV-2006-1943 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: article-manager-multi-scripts-path-disclosure(26676) vdb-entryx_transferred
- securityfocus.com: 20060522 Alstrasoft Article Manager Pro v1.6 mailing-listx_transferred