Vulnerabilities > CVE-2005-2895 - Unspecified vulnerability in Pblang 4.65
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN pblang
nessus
Summary
setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error message.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | PBLANG_MULT_FLAWS.NASL |
description | The remote host is running PBLang, a bulletin board system that uses flat files and is written in PHP. The version of PBLang installed on the remote suffers from several vulnerabilities, including remote code execution, information disclosure, cross-site scripting, and path disclosure. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19594 |
published | 2005-09-08 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19594 |
title | PBLang 4.65 Multiple Vulnerabilities |
code |
|
References
- http://marc.info/?l=bugtraq&m=112611338417979&w=2
- http://marc.info/?l=bugtraq&m=112611338417979&w=2
- http://securitytracker.com/alerts/2005/Sep/1014861.html
- http://securitytracker.com/alerts/2005/Sep/1014861.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22191
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22191