|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
CommonSpot Content Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when 'loader.cfm' is accessed with an invalid 'url' parameter, which will disclose the full path to the 'loader.cfm' script, resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
CommonSpot Content Server
 |
4.5 |
|
|
|
|
|
Credit |
- r0t - krustevs
googlemail.com - UNSECURED SYSTEMS
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|