Vulnerabilities > CVE-2005-0780 - Unspecified vulnerability in PHP Arena Pafiledb

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
php-arena
exploit available

Summary

paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.

Exploit-Db

descriptionPAFileDB 3.1 Error Message Path Disclosure Vulnerability. CVE-2005-0780. Webapps exploit for php platform
idEDB-ID:24798
last seen2016-02-03
modified2004-12-04
published2004-12-04
reportery3dips
sourcehttps://www.exploit-db.com/download/24798/
titlePAFileDB 3.1 Error Message Path Disclosure Vulnerability