Title: Contrexx CMS version.xml Information Disclosure
Info
Disclosure
Jul 22, 2005
Discovery
Jul 08, 2005
Dates
Exploit
Jul 22, 2005
Solution
Unknown
Description
Contrexx CMS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker directly requests the version.xml script, which will disclose the installation version resulting in a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Public
OSVDB:
Web Related
Solution
Upgrade to version 1.0.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.