Vulnerabilities > CVE-2004-2588 - Unspecified vulnerability in XMB Software XMB Forum 1.9Nexusbeta
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Statements
contributor | |
lastmodified | 2008-12-11 |
organization | XMB |
statement | XMB versions 1.9.8 and later were checked and are not vulnerable. |
References
- http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html
- http://www.securityfocus.com/bid/9983
- http://www.osvdb.org/4643
- http://securitytracker.com/id?1009561
- http://marc.info/?l=bugtraq&m=108032355905265&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15656
- https://docs.xmbforum2.com/index.php?title=Security_Issue_History