5
CVSSv2

CVE-2007-2780

Published: 21/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PsychoStats 3.0.6b and previous versions allows remote malicious users to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

psychostats psychostats 2.0.1

psychostats psychostats 2.0

psychostats psychostats

psychostats psychostats 2.1

psychostats psychostats 2.2.1

psychostats psychostats 2.2.2

psychostats psychostats 2.2.4

psychostats psychostats 2.2

psychostats psychostats 2.3

Exploits

source: wwwsecurityfocuscom/bid/24039/info PsychoStats is prone to a path-disclosure issue when invalid data is submitted Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks against a vulnerable computer PsychoStats 306b and prior versions are vulnerable to this issue ht ...