Vulnerabilities > CVE-2006-6113 - Denial-Of-Service vulnerability in James Greenwood Monkey Boards 0.3.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Monkey Boards 0.3.5 allows remote attackers to obtain sensitive information via direct requests to (1) include/admin_auth.inc.php and (2) include/engine/class.compiler.php, which reveals the full path in an error message. NOTE: this issue is only an exposure if the administrator has changed the default script path.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050969.html
- http://sourceforge.net/tracker/index.php?func=detail&aid=1603389&group_id=165094&atid=834302
- http://www.netvigilance.com/advisory0009
- http://www.osvdb.org/30683
- http://www.osvdb.org/30684
- http://www.securityfocus.com/archive/1/452994/100/0/threaded