Vulnerabilities > CVE-2006-2893 - Unspecified vulnerability in Gantty 1.0.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
index.php in GANTTy 1.0.3 allows remote attackers to obtain the full path of the web server via an invalid lang parameter in an authenticate action.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://secunia.com/advisories/20498
- http://secunia.com/advisories/20498
- http://securityreason.com/securityalert/1060
- http://securityreason.com/securityalert/1060
- http://www.securityfocus.com/archive/1/436125/100/0/threaded
- http://www.securityfocus.com/archive/1/436125/100/0/threaded
- http://www.securityfocus.com/bid/18296
- http://www.securityfocus.com/bid/18296
- http://www.vupen.com/english/advisories/2006/2188
- http://www.vupen.com/english/advisories/2006/2188
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26964
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26964