|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
Phprofession contains a flaw that may allow a malicious user to reveal the installation path of the software. The issue is triggered when accessing "upload.php" directly. It is possible that the flaw may allow expose information about the HTTP server's file system resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
phProfession
 |
2.5.4 |
|
|
|
|
Credit |
- Janek Vind "waraxe" - come2waraxe
yahoo.com - Personal Page
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|