Siteframe CMS 2.2.4 - 'download.php' Information Disclosure

EDB-ID:

22386

CVE:





Platform:

PHP

Date:

2003-03-19


source: https://www.securityfocus.com/bid/7143/info

Siteframe has been reported vulnerable to an information disclosure vulnerability.

When handling certain download requests Siteframe may be lead into an error condition. When these errors occur, the script will output some path information. 

Information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system.

http://www.example.com/download.php?id=2%