|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
phpAdsNew contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the upload feature is misused to download files from the server, which will disclose sensitive information resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 2.0beta6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
PHPAdsNew
 |
2.0 Beta 1 |
2.0 Beta 2 |
2.0 Beta 3 |
2.0 Beta 4 |
2.0 Beta 5 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|