Vulnerabilities > CVE-2007-1236 - Unspecified vulnerability in Sitex
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to calendar_events.php, which reveals the path in various error messages.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://osvdb.org/33155
- http://osvdb.org/33155
- http://osvdb.org/33156
- http://osvdb.org/33156
- http://securityreason.com/securityalert/2373
- http://securityreason.com/securityalert/2373
- http://www.securityfocus.com/archive/1/461305/100/0/threaded
- http://www.securityfocus.com/archive/1/461305/100/0/threaded