4.3
CVSSv2

CVE-2008-2028

Published: 30/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote malicious users to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

minibb minibb

Exploits

# Author: __GiReX__ # Homepage: girexaltervistaorg # Date: 21/04/2008 # CMS: miniBB 22 (and maybe prior) # Site: minibbnet # Bug 1: Full Path Disclosure # Bug 2: Cross Site Scripting # Bug 3: Remote SQL Injection # Need: register_globals = On --------------------------------------- # 21/04/2008 Vendor informed # 22/04/2008 miniBB 22a ...