5
CVSSv2

CVE-2011-5075

Published: 29/01/2012 Updated: 02/02/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

translate.php in Support Incident Tracker (aka SiT!) 3.45 up to and including 3.65 allows remote malicious users to obtain sensitive information via a direct request using the save action, which reveals the installation path.

Vulnerable Product Search on Vulmon Subscribe to Product

sitracker support incident tracker 3.61

sitracker support incident tracker 3.62

sitracker support incident tracker 3.63

sitracker support incident tracker 3.64

sitracker support incident tracker 3.65

sitracker support incident tracker 3.45

sitracker support incident tracker 3.50

sitracker support incident tracker 3.6

sitracker support incident tracker 3.51

sitracker support incident tracker 3.60

Exploits

<?php /* ------------------------------------------------------------------------------ Support Incident Tracker <= 365 (translatephp) Remote Code Execution Exploit ------------------------------------------------------------------------------ author: Egidio Romano aka EgiX mail: n0b ...